Harvester APT Expands Spying Operations with New GoGra Linux Malware

2026-04-23T20:51:47Z9b0ec7c4f3e802c03a94b7630d55b43b96192c4f538fdb4adaf07e8f3d245de6
313 TeamAI assistantsAnthropicClaude MythosDDoSDLL sideloadingGitHub CopilotGoGraHarvester APTIndiaIran-linkedLOTUSLITELinux malwareMicrosoft APIsMicrosoft vulnerabilitiesMustang PandaSouth AsiaSouth Koreacloud security','threat intelligence','intel scrapingcovert C2critical flawsfake PDFhidden website codeprompt injectionvendor breach

What happened

HackRead roundup (Apr 21–23, 2026) reports multiple active threats: Harvester APT has deployed a new GoGra Linux malware campaign in South Asia using fake PDFs and Microsoft APIs for covert C2; Forcepoint disclosed indirect prompt‑injection attacks that hide instructions in website code to manipulate AI assistants (e.g., GitHub Copilot); Anthropic is investigating a vendor-related access to its Claude Mythos model after a Discord‑linked group interaction; Mustang Panda is using an updated LOTUSLITE DLL‑sideloading backdoor against Indian banks and Korean diplomats; Iran‑linked 313 Team claimed

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
hackread
Record identifier
9b0ec7c4f3e802c03a94b7630d55b43b96192c4f538fdb4adaf07e8f3d245de6
Enrichment time
2026-04-23T20:51:47Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.