Graphican
- First seen
- 2020-04-01 00:00:00
- Malware type
- backdoor
- Profile updated
- 2026-07-07 15:04:16
Targeted industries: government-and-public-sector defense-and-aerospace
Targeted regions: country_code:gb country_code:us
Context
According to Symantec, Graphican is an evolution of the known APT15 backdoor Ketrican, which itself was based on a previous malware - BS2005 - also used by APT15. Graphican has the same basic functionality as Ketrican, with the difference between them being Graphican’s use of the Microsoft Graph API and OneDrive to obtain its command-and-control (C&C) infrastructure.
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Win_Graphican_Auto (yara-rule)
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Win.Graphican (report)
- Broadcom/Symantec — Flea Backdoor Microsoft Graph Apt15 (report)