EXECUTIVE SUMMARY
There is a concerning trend emerging in cyber threats where attackers are increasingly exploiting the Microsoft Graph API for malicious purposes, particularly for establishing command-and-control (C&C) infrastructure on Microsoft cloud services. Recently, an organization in Ukraine fell victim to a previously undocumented malware named BirdyClient, which utilized the Graph API to leverage Microsoft OneDrive for its C&C operations.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY
There is a concerning trend emerging in cyber threats where attackers are increasingly exploiting the Microsoft Graph API for malicious purposes, particularly for establishing command-and-control (C&C) infrastructure on Microsoft cloud services. Recently, an organization in Ukraine fell victim to a previously undocumented malware named BirdyClient, which utilized the Graph API to leverage Microsoft OneDrive for its C&C operations.[emaillocker id="1283"]
BirdyClient, also known as OneDriveBirdyClient, camouflaged itself by adopting the file name vxdiff.dll, identical to a legitimate DLL associated with Apoint driver software. This malware's primary functionality revolves around connecting to the Microsoft Graph API to utilize OneDrive as a C&C server. Notably, it generates a specific log file in the system. This incident isn't isolated; prior instances include the North Korea-linked Vedalia group's Bluelight and the Harvester group's Backdoor.Graphon, both employing the Graph API for C&C operations. Furthermore, the Graph API's exploitation gained further prominence with Graphite, attributed to the Russian Swallowtail espionage group. Subsequent developments saw other threat actors, like Flea (APT15), adopting similar tactics with variants like Backdoor.Graphican.
The increasing adoption of the Microsoft Graph API in cyber threats poses significant challenges for cybersecurity professionals. Attackers' preference for leveraging Graph API stems from its inconspicuous nature, as traffic to popular cloud services may evade detection. Moreover, it offers attackers a cost-effective and secure infrastructure. As evidenced by the evolution of malware variants and the development of tools like GraphStrike, it's evident that threat actors are continuously innovating. Heightened awareness and proactive measures are imperative to counter this evolving threat landscape effectively.
THREAT PROFILE:
| Tactic | Technique Id | Technique |
| Execution | T1059 | Command and Scripting Interpreter |
| T1204 | User Execution | |
| Defense Evasion | T1036 | Masquerading |
| Discovery | T1087 | Account Discovery |
| T1538 | Cloud Service Dashboard | |
| T1082 | System Information Discovery | |
| Command and Control | T1105 | Ingress Tool Transfer |
| Impact | T1485 | Data Destruction |
REFERENCES:
The following reports contain further technical details:
https://thehackernews.com/2024/05/hackers-increasingly-abusing-microsoft.html