Harvester, also tracked as Harvester APT and harvester_apt, is a cyberespionage group active since at least June 2021 and assessed as nation-state-backed. Its operations focus on South Asia, particularly Afghanistan, targeting telecommunications, government, information technology, and media organizations. No specific sponsoring country has been established. Harvester combines custom malware with publicly available offensive tools, including Cobalt Strike Beacon and Metasploit. Its early Windows toolset included the .NET-based Graphon backdoor, a custom downloader, and a screenshot utility. Graphon provides remote command execution and exfiltrates encrypted command output. The screenshot utility packages captured images in password-protected archives for exfiltration. Windows persistence has included registry Run entries. The group uses legitimate Microsoft cloud infrastructure and CloudFront services to blend command-and-control traffic with ordinary network activity. Harvester's GoGra backdoor extends its espionage capabilities across Windows and Linux. GoGra uses the Microsoft Graph API and Outlook mailboxes for command-and-control, authenticating with embedded Azure AD application credentials. It retrieves encrypted commands from email messages, executes them locally, and returns encrypted results through reply messages. After processing tasking, it deletes the original messages to reduce forensic traces. The Windows and Linux variants share closely matching code and command-and-control logic. Linux infection chains use social engineering and regionally tailored decoy documents, presenting malicious ELF executables as document files. A Go-based dropper displays a decoy while deploying the backdoor. Linux persistence relies on systemd user services and XDG autostart entries, with components masquerading as the legitimate Conky system monitor. These techniques support sustained access, covert command execution, and information collection while reducing the visibility of malicious activity.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
36 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
10 malware families attributed to this actor across reporting.
5 additional families tracked in Mallory.
28 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Espionage activity targeting Linux and previously Windows systems in South Asia using custom backdoors and Microsoft services as covert command-and-control infrastructure.
Espionage group active since at least 2021 targeting telecommunications, government, and IT organizations in South Asia using custom tools, including the GoGra backdoor delivered through Microsoft Outlook infrastructure via the Microsoft Graph API.
Espionage-focused activity in South Asia using a new Linux variant of the GoGra backdoor that abuses Microsoft Graph API and Outlook mailboxes as a covert command-and-control channel.
Cyberespionage group expanding its cross-platform tooling with a Linux version of the GoGra backdoor that uses Microsoft Graph API and Outlook mailboxes as a covert C2 channel, with apparent targeting interest in South Asia.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.