Skip to content
← All Threat Actors
Nation-State high South Asia (assessed)

Harvester

Nation-state (South Asia nexus — India-assessed, not publicly attributed) · Espionage / intelligence collection

Reports 1
Active Since 2021
Last Reported 3 Jun 2026
Sectors Targeted communications, critical-infrastructure

Tactics, Techniques & Procedures (TTPs)

  • GoGra backdoor (Go-based) using Microsoft Outlook via Graph API as C2 relay — traffic indistinguishable from legitimate Microsoft 365 activity
  • Linux-native GoGra variant (2026) extending targeting beyond Windows to server and telecoms infrastructure
  • Backdoor.Graphon (Windows, custom) — predecessor implant with identical Graph API C2 design
  • C2 via hardcoded Microsoft Entra ID application credentials polling a controlled Outlook mailbox folder
  • Custom screenshot utilities and file staging tools alongside backdoor
  • Targeting of government and telecoms back-end infrastructure with sustained multi-year persistence

Known Targets

Government ministries in Afghanistan and IndiaTelecommunications operators in South AsiaIT organisations in geopolitically contested regionMedia organisations in South Asia

Analyst Notes

First documented by Symantec in November 2021 following intrusion activity against Afghan entities coinciding with the final period of NATO presence. Attribution to a specific state has not been publicly made; South Asian nexus is assessed on the basis of targeting priorities. The group's defining technical signature — routing C2 through legitimate Microsoft cloud APIs — predates wider APT adoption of this technique, indicating early investment in cloud-infrastructure evasion. The April 2026 Linux variant extends operational reach to server environments (email servers, web infrastructure, telecoms back-ends) that typically run Linux and sit outside Windows-centric EDR coverage.

Also Known As

Harvester (Symantec designation)