#FINALDRAFTmalware
FINALDRAFT malware, used in a South American foreign ministry attack (November 2024), leverages Microsoft Graph API for C2. The C++ malware, also found on Linux, uses Outlook drafts for command execution and process injection. Attribution to REF7707.#FINALDRAFTmalware
February 13, 2025 at 10:05 AM
FinalDraft malware uses Outlook drafts (r/p_) for stealthy C&C via Microsoft Graph API. 37 commands (data exfiltration, etc.) are supported; a Linux version exists. Targeted South America & possibly Southeast Asia (REF7707).#FinalDraftMalware
February 17, 2025 at 12:31 AM