"Microsoft Graph API Emerges as a Top Attacker Tool to Plot Data Theft"
"Microsoft Graph API Emerges as a Top Attacker Tool to Plot Data Theft"
There has been a rise in the use of native Microsoft services by nation-state espionage actors for their Command-and-Control (C2) needs. In recent years, several unrelated groups have realized that using Microsoft's services against their targets is cheaper and more effective than building and maintaining their own infrastructure. Besides saving money and hassle by not having to build and maintain their own infrastructure, using legitimate services lets attackers blend in with legitimate network traffic.