GraphDrop
Aliases: GraphicalProton, SPICYBEAT
- First seen
- 2022-11-15 00:00:00
- Malware type
- downloader, loader, rat
- Family
- Malware family
- Profile updated
- 2026-07-07 14:50:46
Targeted industries: government-and-public-sector technology-and-telecommunications financial-services
Context
PANW Unit 42 describes this malware as capable of up and downloading files as well as loading additional shellcode payloads into selected target processes. It uses the Microsoft Graph API and Dropbox API as C&C channel.
Detection coverage
- 2 YARA rules
Exploited vulnerabilities
- CVE-2023-42793 (vulnerability)
Detection rules
- MALPEDIA_Win_Graphdrop_Auto (yara-rule)
- DITEKSHEN_MALWARE_Win_Graphicalproton_Rsockstun (yara-rule)
Reports & references
- Mandiant — Apt29 Evolving Diplomatic Phishing (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Graphdrop (report)
- Palo Alto Unit 42 — Cloaked Ursa Phishing (report)
- avertium.com — Evolution Of Russian Apt29 New Attacks And Techniques Uncovered (report)
- CISA — Aa23 347A (report)
- go.recordedfuture.com — Cta 2023 0727 1 (report)
- fortinet.com — Teamcity Intrusion Saga Apt29 Suspected Exploiting Cve 2023 42793 (report)