An increasing number of threats have begun to leverage the Microsoft Graph API, usually to facilitate communications with command-and-control (C&C) infrastructure hosted on Microsoft cloud services.
The technique was most recently used in an attack against an organization in Ukraine, where a previously undocumented piece of malware used the Graph API to leverage Microsoft OneDrive for C&C purposes.
Read more…
Source: Symantec
Related:
- Immediately Patch Windows 0-Day Flaw That’s Being Used to Spread Spyware
September 13, 2017
Windows 0-Day Flaw Get ready to install a fairly large batch of security patches onto your Windows computers. As part of its September Patch Tuesday, Microsoft has released a large batch of security updates to patch a total of 81 CVE-listed vulnerabilities, on all supported versions of Windows and other MS products. The latest security update addresses ...
- Microsoft Programming Error is Behind Dangerous Kernel Bug, Researchers Claim
September 7, 2017
Researchers claim a programming error in the Microsoft Windows kernel cracks the door open for malicious executables to bypass security software. The flaw, according to security firm EnSilo, has been present on previous versions of Windows dating back to Windows 2000 and can be found on Windows 10 as well. “The bug is a programming error ...
- NHS Digital does new cyber security deal with Microsoft
August 16, 2017
NHS Digital has set up an agreement with Microsoft that will provide support in detecting cyber threats to IT systems relying on outdated operating systems until the middle of next year The provider of data and IT services for health and social care bodies has reached a custom support agreement with the software giant that will ...
- Microsoft announces huge bug bounty rewards for security flaws
July 27, 2017
Microsoft has announced the Windows Bounty Program with rewards as high as $250,000 for users who can find bugs in Windows 10. While the company has had a number of previous bug bounty programs, this is the first one to target features in its Windows operating system specifically. Microsoft’s new program not only covers Windows 10 but ...
- Microsoft’s Private Windows 10 Internal Builds and Partial Source Code Leaked Online
June 23, 2017
A massive archive of Microsoft’s top-secret Windows 10 builds, and the source codes for private software has been reportedly leaked online, which could lead to a nasty wave of Windows 10 exploits, journalist at the Reg claims. The Leaked files – uploaded on BetaArchive website – contains more than 32 terabytes of data, which includes many ...
- Brutal Kangaroo: CIA-developed Malware for Hacking Air-Gapped Networks Covertly
June 22, 2017
WikiLeaks has published a new batch of the ongoing Vault 7 leak, this time detailing a tool suite – which is being used by the CIA for Microsoft Windows that targets “closed networks by air gap jumping using thumb drives,” mainly implemented in enterprises and critical infrastructures. Air-gapped computers that are isolated from the Internet or ...

