Graphican

First seen
2020-04-01 00:00:00
Malware type
backdoor
Profile updated
2026-07-07 15:04:16

Targeted industries: government-and-public-sector defense-and-aerospace

Targeted regions: country_code:gb country_code:us

Context

According to Symantec, Graphican is an evolution of the known APT15 backdoor Ketrican, which itself was based on a previous malware - BS2005 - also used by APT15. Graphican has the same basic functionality as Ketrican, with the difference between them being Graphican’s use of the Microsoft Graph API and OneDrive to obtain its command-and-control (C&C) infrastructure.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Graphican_Auto (yara-rule)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Win.Graphican (report)
  • Broadcom/Symantec — Flea Backdoor Microsoft Graph Apt15 (report)

External references