The likely nation-state-backed Harvester group has expanded its espionage operations in South Asia with a new Linux variant of its GoGra backdoor, extending a toolset previously associated with Windows intrusions. Researchers linked the malware to Harvester through near-identical code, shared command-and-control logic, and matching spelling errors, and said the backdoor uses the Microsoft Graph API and Outlook mailboxes as a covert C2 channel to blend malicious traffic with legitimate cloud activity. Initial submissions tied to the malware came from India and Afghanistan, and the use of localized decoy documents indicates a tailored campaign against regional targets.
Harvester has been active since at least 2021 and was previously observed targeting telecommunications, government, and IT organizations, particularly in Afghanistan, with custom malware including Backdoor.Graphon, a downloader, and a screenshot utility, alongside Cobalt Strike Beacon and Metasploit. In both earlier and newer activity, the group abused legitimate Microsoft infrastructure to evade perimeter defenses; the Linux GoGra sample persists through a systemd user service and an XDG autostart entry, then executes commands delivered through encrypted email messages. The campaign shows Harvester building a cross-platform espionage capability while maintaining a consistent focus on South Asian victims.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Researchers said initial VirusTotal submissions for the Linux GoGra malware came from India and Afghanistan, indicating likely targeting in those countries. They also noted localized decoy documents consistent with a tailored espionage campaign aimed at South Asia.
Symantec and the Carbon Black Threat Hunter Team reported that Harvester expanded its toolset with a Linux version of the GoGra backdoor. The malware uses Microsoft Graph API and Outlook mailboxes as a covert command-and-control channel and was linked to Harvester through strong code similarities with earlier Windows samples.
During the 2021 campaign, Harvester deployed custom malware including the Graphon backdoor, a downloader, and a screenshot utility, alongside Cobalt Strike Beacon and Metasploit. The group used Microsoft Azure Websites and CloudFront infrastructure for command-and-control to blend malicious traffic with legitimate services.
Symantec published research describing Harvester as a previously unseen, likely nation-state-backed espionage actor. The report said the campaign had been observed from June through October 2021 and highlighted its focus on South Asian targets.
Harvester activity began in June 2021, targeting organizations in South Asia, particularly in Afghanistan. Victims were identified in the telecommunications, government, and IT sectors.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
broadcom.com
Open sourcesecurity.com
Open sourcesecurity.com
Open sourcesymantec-enterprise-blogs.security.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.