Threat Intelligence

HollowGraph malware uses Microsoft 365 calendar for command and control

Privacy concept: pixelated words Malware on digital background, 3d render

A new malware component called HollowGraph has been identified by Group-IB that leverages the calendar feature within compromised Microsoft 365 mailboxes to act as a command-and-control channel, according to a recent report by Bleeping Computer.

HollowGraph, believed to be part of the Cavern command-and-control framework, targets organizations in Israel for espionage purposes. The malware uses hardcoded credentials to authenticate to the Microsoft Graph API via a compromised Microsoft 365 account. It stores its configuration in a file named logAzure.txt, containing tenant IDs, client secrets, and encryption keys. Commands and exfiltrated data are hidden within files attached to calendar events scheduled for May 13, 2050.

HollowGraph supports GET and SEND commands to retrieve instructions and send stolen data, respectively. Communication is secured using a hybrid encryption scheme combining RSA and AES-256-GCM. An additional channel via DNS tunneling is used to update Microsoft Entra ID details. While not definitively attributed to a known actor, technical similarities suggest a link to Iranian-nexus threat actors. Organizations are advised to monitor Microsoft 365 audit logs for suspicious calendar activity and DNS tunneling patterns.

Source: Bleeping Computer

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds