HollowGraph is a newly discovered malware that exploits Microsoft 365 calendar events as a command-and-control (C2) communication channel. The malware utilizes events dated in the far future, specifically 2050, to embed operator instructions and exfiltrate stolen data, evading detection by appearing as legitimate traffic within Microsoft 365 services.
The malware, described as a .NET DLL, operates by using compromised Microsoft 365 mailboxes. Through the Microsoft Graph API, it transforms the mailbox's calendar into a two-way dead-drop. Operator commands are sent as attached files in future-dated events, and similarly, stolen data is encrypted and attached to newly created future events. RSA and AES-256 encryption ensures secure communication.
Group-IB reports identify that HollowGraph predominantly targets entities within Israel, suggesting a strategic espionage effort. This targeted approach is part of a larger toolkit linked to the Iranian threat actor, Cavern Manticore. The malware reportedly infected at least a dozen systems, with three actively communicating with the threat actor during a monitoring period.
Besides using the Microsoft 365 calendar for C2 communications, HollowGraph maintains a secondary channel for refreshing configurations and credentials via DNS tunneling. This includes associated details like Microsoft Entra ID that support ongoing operations and maintain access to compromised systems.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
The newly discovered HollowGraph malware utilizes Microsoft 365 calendar for command-and-control communication, hiding its activity within legitimate traffic. This innovative approach poses significant security risks, especially to targeted entities in Israel and highlights the evolving tactics of cyber threat actors linked to Iranian interests.
New malware known as HollowGraph leverages Microsoft 365 calendar features for command-and-control communications, primarily targeting Israeli entities. This sophisticated method conceals attacker commands and exfiltrated data within calendar events, indicating a significant advancement in cyber espionage techniques.
A new malware named HollowGraph uses Microsoft 365 calendars to send commands and exfiltrate data. By embedding instructions and stolen files in events set for the year 2050, it disguises its activity as legitimate traffic to evade detection.