Skip to content

Malware

GraphDrop

aka GraphicalProton · SPICYBEAT

PANW Unit 42 describes this malware as capable of up and downloading files as well as loading additional shellcode payloads into selected target processes.

GraphDrop, also known as GraphicalProton, SPICYBEAT, is a Windows malware family operated by APT29.

Background

PANW Unit 42 reports that this malware can both upload and download files and inject further shellcode payloads into chosen target processes. For its C&C channel it makes use of the Microsoft Graph API and the Dropbox API.


Source: Malpedia (Fraunhofer FKIE).