New HollowGraph malware uses Microsoft Graph for stealthy C2 comms

New HollowGraph malware uses Microsoft Graph for stealthy C2 comms
HollowGraph abuses the calendar feature in compromised Microsoft 365 mailboxes as a covert command-and-control channel to receive instructions and exfiltrate stolen data. Group-IB says the malware is likely part of the Cavern framework and is being used in targeted espionage against organizations in Israel. #HollowGraph #Cavern #Microsoft365 #MicrosoftGraph #Lyceum

Keypoints

  • HollowGraph uses Microsoft 365 calendar entries to hide commands and stolen files.
  • The malware authenticates to Microsoft Graph with hardcoded credentials from a fake log file named logAzure.txt.
  • It creates future-dated calendar events to act as a covert dead-drop for attacker communication.
  • HollowGraph also uses DNS tunneling through cloudlanecdn[.]com to refresh Entra ID configuration data.
  • Group-IB links the activity to the Cavern framework and suspects an Iranian-nexus operation focused on Israel.

Read More: https://www.bleepingcomputer.com/news/security/new-hollowgraph-malware-uses-microsoft-graph-for-stealthy-c2-comms/