Malware
Grager
Grager is a backdoor deployed against three organizations in Taiwan, Hong Kong, and Vietnam in April 2024.
Grager is a Windows malware family.
Background
Grager is a backdoor used against three organizations in Taiwan, Hong Kong, and Vietnam during April 2024. Analysis showed it relies on the Graph API to reach a command-and-control (C&C) server hosted on Microsoft OneDrive, decrypting a OneDrive client ID and refresh token from a blob embedded in its own file body. It supports the following commands:
- Retrieve machine information, including machine name, user, IP address, and machine architecture
- Download or upload a file
- Execute a file
- Gather file system information, including available drives, their sizes, and types of drives
Source: Malpedia (Fraunhofer FKIE).