Revoking the token didn’t kill the backdoor

Summary

A custom implant named GraphWorm, associated with the China-nexus APT group Webworm, utilizes Microsoft Graph and OneDrive for its command and control (C2) channel. This backdoor's design allows operators to bypass traditional C2 blocking methods by leveraging existing Microsoft 365 infrastructure for task execution and data exfiltration.

IFF Assessment

FOE

This article details a sophisticated backdoor that circumvents standard incident response procedures like token revocation, posing a significant challenge for defenders.

Defender Context

Defenders must be aware of APTs leveraging legitimate cloud services like Microsoft Graph and OneDrive for C2, as traditional network-based detection methods may be ineffective. Incident response playbooks need to be updated to account for implants that use cloud storage as dead drops, focusing on behavioral analysis and compromise artifact identification rather than solely network indicators.

Read Full Story →