Hackers Increasingly Abusing Microsoft Graph API for Stealthy Malware Communications
To avoid detection, threat actors have begun using Microsoft Graph API more and more as a weapon.
This is done to "enable communications with command-and-control (C&C) infrastructure hosted on Microsoft cloud services," according to a report published with The Hacker News by the Symantec Threat Hunter Team, a division of Broadcom.
Several nation-state-aligned hacker groups have been seen utilizing Microsoft Graph API for C&C from January 2022. Threat actors identified as APT28, REF2924, Red Stinger, Flea, APT29, and OilRig are among those included in this.
Before its widespread use, the Microsoft Graph API was first observed in June 2021 about an activity cluster known as Harvester. The activity cluster was using a specialized implant called Graphon, which used the API to...

