Microsoft Graph is becoming a popular target for hackers

Multiple hacker collectives are actively using the Microsoft Graph API to hide their communications with the command and control (C2) infrastructure hosted on Microsoft cloud services, cybersecurity researchers from the Symantec Threat Hunter Team have revealed.

The researchers claim that groups such as APT28, REF2924, Red Stinger, Flea, APT29 and Oilrig have been using this technique for two and a half years now to stay out of sight. Among the targets is an unnamed organization from Ukraine, which was infected with a previously unknown malware variant called BirdyClient.