Harvester is a likely nation-state-backed cyberespionage threat actor active since at least 2021 and focused primarily on South Asia. The group was first associated with information-stealing intrusions against telecommunications, government, and information technology organizations, with observed targeting that particularly included Afghanistan and later likely India. Harvester’s operations are characterized by espionage-oriented collection rather than disruptive or financially motivated activity. Harvester uses a mix of bespoke malware and publicly available offensive tooling. Its known custom malware includes Backdoor.Graphon and GoGra. Graphon is a Windows backdoor that abuses Microsoft cloud infrastructure, including Microsoft Graph API-related services, for command and control. It supports remote command execution and encrypted exfiltration, and Harvester paired it with additional custom components such as a downloader and screenshot capture tooling. Public tools observed in Harvester intrusions include Cobalt Strike Beacon and Metasploit. The actor has expanded from Windows-focused operations to cross-platform tooling with a Linux variant of GoGra. That malware uses Microsoft Graph API and Outlook mailboxes as a covert command-and-control channel, blending malicious traffic with legitimate Microsoft cloud communications. Reported Linux tradecraft includes social-engineering delivery using decoy documents tailored to South Asian themes, execution of attacker commands via shell, encrypted return of results, deletion of tasking messages to reduce forensic visibility, and persistence through systemd user services and XDG autostart entries. Strong code similarities between Linux GoGra and Harvester’s earlier Windows tooling indicate common development and an active effort to broaden platform coverage. Harvester consistently demonstrates defense-evasion tradecraft through use of legitimate cloud services for command and control, encrypted tasking and exfiltration, stealthy persistence, and malware disguised as benign documents. Victimology, custom tooling, and operational behavior support assessment of Harvester as a state-linked espionage actor. The alias "Harvester APT" appears in reporting, but no specific state sponsor is confirmed at high confidence.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
36 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
10 malware families attributed to this actor across reporting.
5 additional families tracked in Mallory.
28 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Espionage activity targeting Linux and previously Windows systems in South Asia using custom backdoors and Microsoft services as covert command-and-control infrastructure.
Espionage group active since at least 2021 targeting telecommunications, government, and IT organizations in South Asia using custom tools, including the GoGra backdoor delivered through Microsoft Outlook infrastructure via the Microsoft Graph API.
Espionage-focused activity in South Asia using a new Linux variant of the GoGra backdoor that abuses Microsoft Graph API and Outlook mailboxes as a covert command-and-control channel.
Cyberespionage group expanding its cross-platform tooling with a Linux version of the GoGra backdoor that uses Microsoft Graph API and Outlook mailboxes as a covert C2 channel, with apparent targeting interest in South Asia.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.