Graphon, also known as Backdoor.Graphon, is a custom Windows backdoor written in .NET and used by the Harvester cyberespionage group. It uses the Microsoft Graph API to communicate with command-and-control infrastructure hosted on legitimate Microsoft services, helping malicious communications blend with normal cloud traffic. Its functionality includes remote command execution and AES-encrypted command-and-control communications. Graphon was associated with Harvester's information-stealing operations targeting telecommunications, government, and information technology organizations in South Asia, with activity dating to June 2021. It is functionally similar to GoGra, another Harvester backdoor written in Go, but differs in implementation and some command-handling features. The Linux variants associated with this toolset belong to GoGra rather than establishing Linux support for Graphon.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Its toolset included a custom backdoor called Backdoor.Graphon that used the Graph API to communicate with Microsoft infrastructure for C&C purposes.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
"GoGra ... uses the Microsoft Graph API to interact with a command-and-control (C&C) server hosted on Microsoft mail services..."; "Grager ... used the Graph API to communicate with a C&C server hosted on Microsoft OneDrive"; "Onedrivetools ... authenticates to Microsoft Graph API and downloads the second stage payload from OneDrive... fetching the new commands to execute from a file called cmd"
The malware uses the legitimate Microsoft Graph API and Outlook mailboxes as a covert command-and-control (C2) channel, allowing it to bypass traditional perimeter network defenses.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A custom Windows backdoor associated with Harvester. It is described as highly similar to GoGra and also uses Microsoft infrastructure for command-and-control activity.
A backdoor similar to GoGra that relies on Microsoft infrastructure for command-and-control.
A bespoke implant used by Harvester in an information-stealing campaign targeting South Asia. It leveraged the Microsoft Graph API for command-and-control communications.
A custom backdoor associated with Harvester that is similar to GoGra and uses Microsoft infrastructure for command-and-control.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.