HollowGraph is a newly discovered malware that abuses Microsoft 365 calendar events and the Microsoft Graph API for covert command-and-control communication. Group-IB says it may be linked to Cavern Manticore and shows signs of targeted activity against Israeli entities, using encrypted calendar attachments, DNS tunneling, and Microsoft Entra ID credentials. #HollowGraph #CavernManticore #MicrosoftGraphAPI #MicrosoftEntraID #Israel
Keypoints
- HollowGraph uses Microsoft 365 calendar events for stealthy C&C communication.
- The malware hides traffic inside the Microsoft Graph API and a compromised Israeli mailbox.
- Operators use calendar events as a dead-drop for tasks and exfiltrated files.
- HollowGraph also uses DNS tunneling to refresh configuration and authentication credentials.
- Group-IB found 12 victims and suspects a link to Cavern Manticore and Lyceum.