Group-IB has uncovered HollowGraph, a .NET espionage implant that uses a hijacked Microsoft 365 calendar and Microsoft Graph API traffic to receive instructions and exfiltrate stolen files through far-future calendar events. The campaign also uses DNS to refresh Entra ID client-credential details, and Group-IB links the implant to Cavern with high confidence but does not confidently attribute the operation to a known threat actor. #HollowGraph #Microsoft365 #MicrosoftGraph #EntraID #Cavern #cloudlanecdn
Keypoints
- HollowGraph uses a compromised Microsoft 365 calendar as a two-way dead drop.
- The implant pulls instructions from a far-future event dated 2050-05-13.
- Stolen files are encrypted and uploaded as calendar attachments for exfiltration.
- A DNS channel refreshes Entra ID client credentials from cloudlanecdn[.]com.
- Group-IB links HollowGraph to Cavern, but the operator remains unattributed.
Read More: https://thehackernews.com/2026/07/hollowgraph-malware-hides-c2-and-stolen.html