Netskope Threat Labs

GoGra

ATP Sandbox Adv. HeuristicsAV

GoGra is a backdoor written in Go that Symantec observed deployed against a media organization in South Asia in late 2023. It uses the Microsoft Graph API to communicate with a command and control server hosted on Microsoft mail services, which blends its traffic into legitimate cloud activity.

First seen
April 2026
Last seen
October 2026
Alert Name
Linux.Backdoor.GoGra
Linux.Trojan.GoGra
Trojan.Linux.GoGra.1
Trojan.Linux.GoGra.2
Trojan.Linux.GoGra.3
Trojan.Linux.GoGra.39850798
Trojan.Linux.GoGra.4