Graphican is a backdoor Symantec says Flea—also called APT15 or Nickel in its reporting—used in a campaign from late 2022 to early 2023 that focused primarily on foreign affairs ministries in the Americas. Its distinguishing feature is how it obtains command-and-control (C&C) information: it queries OneDrive through the Microsoft Graph API, rather than relying on a C&C server address embedded in the observed samples. Symantec assessed that the campaign sought persistent access for intelligence gathering; that is an analytic judgment, not a confirmed statement of the operators’ intent.
Who and what did Symantec report?
Symantec’s Threat Hunter Team reported that Flea had been active since at least 2004 and observed Graphican in a campaign spanning late 2022 to early 2023. The primary focus was foreign affairs ministries in the Americas. Symantec also identified a government finance department in the Americas, a company selling products in Central and South America, and one European victim. The report does not name the ministries or countries, or give a total victim count. Symantec’s campaign report
Symantec uses the name Flea and also refers to the actor as APT15 and Nickel. MITRE ATT&CK’s Ke3chang profile lists APT15 and NICKEL among names associated with Ke3chang, and describes the group as operating out of China. Those are source-specific attribution labels and assessments; the Graphican campaign report alone does not independently prove that every alias refers to one actor or establish state sponsorship. MITRE says Ke3chang targeting spans the Americas, Caribbean, Europe, and North America since at least 2010. That broader profile history is separate from Symantec’s report of Flea activity since at least 2004; neither date establishes an exact founding date. MITRE ATT&CK: Ke3chang (G0004)
What is Graphican, and how does it differ from Ketrican?
Symantec describes Graphican as an evolution of Ketrican, a Flea backdoor itself based on BS2005. The reported distinction is Graphican’s method for retrieving C&C infrastructure: it uses Microsoft Graph API to query OneDrive and derive the server address. The available reporting does not provide a performance benchmark or quantitative comparison of the two backdoors.
#1 Best Overall
| Backdoor | Relationship and reported C&C method |
|---|---|
| BS2005 | Underlying malware on which Ketrican is based, according to Symantec. The report does not describe a Graph API/OneDrive retrieval method for BS2005. |
| Ketrican | Flea backdoor based on BS2005; Graphican is described as its evolution. The campaign report does not describe Ketrican as using Graphican’s OneDrive-based C&C retrieval. |
| Graphican | Evolution of Ketrican that obtains C&C information through Microsoft Graph API and OneDrive, according to Symantec. |
How does Graphican use Microsoft Graph and OneDrive?
In Symantec’s analysis, Graphican does not begin with a hardcoded C&C server address. Instead, the observed samples shared API authentication parameters and used OneDrive as a place to retrieve the address. The reported sequence is:
- Prepare Internet Explorer: change registry settings to disable first-run prompts, then check for
iexplore.exe. - Access the browser interface: create an
IWebBrowser2COM object and use it to authenticate to the Microsoft Graph API. - Look up the server address: enumerate OneDrive contents under the “Person” folder. Graphican decrypts the name of a child folder to obtain the C&C server address.
- Register the infected machine: construct a bot identifier from host and system information and register with C&C.
- Poll for instructions: continue checking for operator commands and carry them out.
Using a cloud API this way can let an operator retrieve or change C&C information without placing the server address directly in the observed malware sample. This describes abuse of the API and OneDrive as infrastructure; it does not mean Microsoft Graph or OneDrive was itself compromised. Symantec compared the technique with a separate APT28/Graphite campaign, while describing the actors as unconnected. Symantec’s technical account
What can Graphican do on a compromised computer?
Symantec says Graphican can receive commands to:
- Open an interactive command line.
- Create files.
- Download files from the infected machine.
- Create processes with a hidden window.
These capabilities give operators a way to interact with a host and retrieve files, based on Symantec’s analysis of the samples it examined. The report does not establish that every capability was used on every victim. Symantec’s command and capability details
Was Graphican the campaign’s only tool?
No. Symantec reports a broader toolkit that included living-off-the-land tools, Ketrican variants, Ewstew, web shells, and credential and reconnaissance tools. SecurityWeek also reported exploitation of CVE-2020-1472, known as Zerologon, in connection with the activity. Microsoft patched Zerologon in August 2020, according to SecurityWeek. The reporting does not establish Zerologon as the campaign’s sole initial-access route, and its use in this historical incident does not by itself indicate a current compromise. Organizations should check Microsoft’s advisories and their own asset exposure when assessing the vulnerability. SecurityWeek’s account of the campaign
Free tools Windows power users keep installed
One-click scans. No signup required.
Why target foreign ministries?
Symantec interpreted the ministry targeting as likely geopolitical and assessed that the group sought to maintain access to networks for intelligence gathering. The team wrote: “The goal of the group does seem to be to gain persistent access to the networks of victims of interest for the purposes of intelligence gathering.” This is Symantec’s assessment of the activity, not a verified admission by the operators or proof of their motive. Symantec Threat Hunter Team
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

