Grager
- First seen
- 2024-04-01 00:00:00
- Malware type
- backdoor
- Family
- Malware family
- Profile updated
- 2026-07-07 15:03:27
Targeted regions: country_code:tw country_code:hk country_code:vn
Context
Grager is a backdoor deployed against three organizations in Taiwan, Hong Kong, and Vietnam in April 2024. Analysis of this backdoor revealed that it uses the Graph API to communicate with a command and control (C&C) server hosted on Microsoft OneDrive. The backdoor decrypts a client ID and refresh token for OneDrive from a blob contained within its file body. It supports the following commands: - Retrieve machine information, including machine name, user, IP address, and machine architecture - Download or upload a file - Execute a file - Gather file system information, including available drives, their sizes, and types of drives
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Win_Grager_Auto (yara-rule)
Reports & references
- security.com — Cloud Espionage Attacks (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Grager (report)