Graphite
- First seen
- 2021-11-01 00:00:00
- Malware type
- downloader, loader
- Profile updated
- 2026-07-07 14:55:03
Targeted industries: government-and-public-sector technology-and-telecommunications
Context
Trellix describes Graphite as a malware using the Microsoft Graph API and OneDrive for C&C. It was found being deployed in-memory only and served as a downloader for Empire.
Detection coverage
- 3 YARA rules
Detection rules
- SEKOIA_Apt_Apt28_Susp_Graphite_Downloader (yara-rule)
- SEKOIA_Apt_Sofacy_Graphitemalware_Generic (yara-rule)
- MALPEDIA_Win_Graphite_Auto (yara-rule)
Reports & references
- cert.ssi.gouv.fr — Certfr 2023 Cti 009 (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Graphite (report)
- trellix.com — Prime Ministers Office Compromised (report)
- blog.cluster25.duskrise.com — In The Footsteps Of The Fancy Bear Powerpoint Graphite (report)