SiestaGraph is a Windows .NET backdoor associated with the espionage intrusion set REF2924. It was publicly documented in December 2022 during an intrusion into the Foreign Affairs Office of an unnamed ASEAN member state. It uses the Microsoft Graph API to communicate through Microsoft 365 Mail and OneDrive, allowing command-and-control traffic to blend with legitimate Microsoft cloud activity.
The implant obtains Graph API access tokens using a hard-coded tenant identifier and OAuth refresh token. It identifies infected systems using session information derived from the process identifier, hostname, username, and operating system. Outlook draft messages carry session information, operator commands, and command results, while OneDrive supports file uploads and downloads. Its default command-polling interval is five seconds and can be changed by the operator.
SiestaGraph supports execution through the Windows command interpreter; enumeration of drives, directories, files, processes, and network connections; process termination; file renaming and deletion; bidirectional file transfer; and screenshot capture. Captured screenshots are Base64-encoded and returned through draft email messages. These functions enable remote control, reconnaissance, and data exfiltration from compromised Windows systems. A variant identified in September 2023 used different command identifiers from earlier versions, demonstrating continued development.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
SIESTAGRAPH is a .NET backdoor that leverages the Microsoft Graph interface, a collection of APIs for accessing various Microsoft services.
SIESTAGRAPH is a .NET backdoor that leverages the Microsoft Graph interface, a collection of APIs for accessing various Microsoft services.
This environment has already seen the emergence of the REF2924 intrusion set (SIESTAGRAPH, NAPLISTENER, SOMNIRECORD, and DOORME).
17 distinct techniques documented for this family, organized by ATT&CK tactic.
The executable renamed itself svchost.exe before installing itself as a service.
The NET command gathers information about open TCP connections from the system's TCP table... This code helps the attacker to get a better insight into the system's purpose within the network.
The NET command gathers information about open TCP connections from the system's TCP table.
After obtaining authentication and session tokens, the malware collects system information and exfiltrates it using a method called sendSession... A session token (sessionToken) is created by concatenating the process ID, machine name, username, and operating system.
SIESTAGRAPH interacts with Microsoft’s GraphAPI for command and control using Outlook and OneDrive... The implant utilizes the Microsoft Graph API to access Microsoft 365 Mail and OneDrive for its C2 communication.
SIESTAGRAPH... uses the Microsoft Graph API to access Microsoft 365 Mail and OneDrive for its C2 communication.
Inspecting the sendSession method we see that it creates an email message and saves it as a draft. Using draft messages is common C2 tradecraft as a way to avoid email interception and inspection... the implant will use the getMessages method to check for any draft emails with commands from the attacker.
5 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A backdoor mentioned for comparison that leverages the Microsoft Graph API to access Microsoft 365 Mail for command-and-control communication.
Previously reported malware family that similarly abuses Outlook mail service via the Microsoft Graph API for command-and-control (referenced as a technique comparison to FINALDRAFT).
Previously reported malware/campaign tooling noted for abusing Microsoft Graph API for command and control, referenced here as an earlier example of the same C2 technique.
Previously reported malware associated with abuse of Microsoft's Graph API for command-and-control communications. It is mentioned as a comparison to FINALDRAFT's Graph API C2 technique.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.