Graphite

First seen
2021-11-01 00:00:00
Malware type
downloader, loader
Profile updated
2026-07-07 14:55:03

Targeted industries: government-and-public-sector technology-and-telecommunications

Context

Trellix describes Graphite as a malware using the Microsoft Graph API and OneDrive for C&C. It was found being deployed in-memory only and served as a downloader for Empire.

Detection coverage

  • 3 YARA rules

Detection rules

  • SEKOIA_Apt_Apt28_Susp_Graphite_Downloader (yara-rule)
  • SEKOIA_Apt_Sofacy_Graphitemalware_Generic (yara-rule)
  • MALPEDIA_Win_Graphite_Auto (yara-rule)

Reports & references

  • cert.ssi.gouv.fr — Certfr 2023 Cti 009 (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Graphite (report)
  • trellix.com — Prime Ministers Office Compromised (report)
  • blog.cluster25.duskrise.com — In The Footsteps Of The Fancy Bear Powerpoint Graphite (report)

External references