Description
GoGra is a backdoor written in Go that Symantec observed deployed against a media organization in South Asia in late 2023. It uses the Microsoft Graph API to communicate with a command and control server hosted on Microsoft mail services, which blends its traffic into legitimate cloud activity.
Stats
- First seen
- April 2026
- Last seen
- October 2026
Alert name variants
| Alert Name |
|---|
| Linux.Backdoor.GoGra |
| Linux.Trojan.GoGra |
| Trojan.Linux.GoGra.1 |
| Trojan.Linux.GoGra.2 |
| Trojan.Linux.GoGra.3 |
| Trojan.Linux.GoGra.39850798 |
| Trojan.Linux.GoGra.4 |