Microsoft Graph API is a tool tracked across 12 threat clusters and 20 intelligence report mentions on ThreatCluster. First observed November 20, 2025; most recent activity July 24, 2026.
The Harvester APT group has launched a Linux variant of its GoGra backdoor, utilizing the Microsoft Graph API and Outlook mailboxes for covert command-and-control operations. This malware is designed to evade…
The China-aligned APT group Webworm has shifted its focus from Asia to Europe, targeting government organizations in Belgium, Italy, Poland, Serbia, and Spain during 2025. ESET researchers identified new backdoors,…
The Project CAV3RN cyberespionage framework has evolved with the introduction of a new communication module, AzureCommunication.dll, which replaces the previous HTTP/WebSocket component. This module utilizes Outlook…
In 2024, ESET identified a new China-aligned APT group named LongNosedGoblin, which targets governmental entities in Southeast Asia and Japan. The group employs a custom toolset, primarily using C#/.NET applications, to…
Group-IB has identified HOLLOWGRAPH, a sophisticated Windows malware that abuses the Microsoft Graph API to covertly exfiltrate files and receive commands through compromised Microsoft 365 calendar events. The malware…
Microsoft has reported a significant cyberattack by the threat actor Storm-2949, which exploited Microsoft Entra ID accounts to conduct a large-scale data theft from Microsoft 365 and Azure environments. The attack…
A dormant Microsoft Outlook add-in has been weaponized, leading to the theft of thousands of login credentials and credit card numbers. This incident marks the first known malicious Office add-in discovered in the wild,…
Microsoft has announced an extension of hotpatch update support for Windows Server 2022 Datacenter: Azure Edition until October 2027. This extension allows organizations to apply security updates without requiring a…
A report from Ontinue reveals that Microsoft Teams' guest access feature allows users to accept invitations from external organizations, which results in the loss of their Defender for Office 365 protections. This…
CrowdStrike has reported on WARP PANDA, a China-linked cyber-espionage group targeting North American legal, technology, and manufacturing firms throughout 2025. The group specializes in covert operations within…