Harvester APT Expands Spying Operations with New GoGra Linux Malware
2026-04-23T20:51:47Z•9b0ec7c4f3e802c03a94b7630d55b43b96192c4f538fdb4adaf07e8f3d245de6
313 TeamAI assistantsAnthropicClaude MythosDDoSDLL sideloadingGitHub CopilotGoGraHarvester APTIndiaIran-linkedLOTUSLITELinux malwareMicrosoft APIsMicrosoft vulnerabilitiesMustang PandaSouth AsiaSouth Koreacloud security','threat intelligence','intel scrapingcovert C2critical flawsfake PDFhidden website codeprompt injectionvendor breach
What happened
HackRead roundup (Apr 21–23, 2026) reports multiple active threats: Harvester APT has deployed a new GoGra Linux malware campaign in South Asia using fake PDFs and Microsoft APIs for covert C2; Forcepoint disclosed indirect prompt‑injection attacks that hide instructions in website code to manipulate AI assistants (e.g., GitHub Copilot); Anthropic is investigating a vendor-related access to its Claude Mythos model after a Discord‑linked group interaction; Mustang Panda is using an updated LOTUSLITE DLL‑sideloading backdoor against Indian banks and Korean diplomats; Iran‑linked 313 Team claimed
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- hackread
- Record identifier
- 9b0ec7c4f3e802c03a94b7630d55b43b96192c4f538fdb4adaf07e8f3d245de6
- Enrichment time
- 2026-04-23T20:51:47Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.