HollowGraph abuses the calendar feature in compromised Microsoft 365 mailboxes as a covert command-and-control channel to receive instructions and exfiltrate stolen data. Group-IB says the malware is likely part of the Cavern framework and is being used in targeted espionage against organizations in Israel. #HollowGraph #Cavern #Microsoft365 #MicrosoftGraph #Lyceum
Keypoints
- HollowGraph uses Microsoft 365 calendar entries to hide commands and stolen files.
- The malware authenticates to Microsoft Graph with hardcoded credentials from a fake log file named logAzure.txt.
- It creates future-dated calendar events to act as a covert dead-drop for attacker communication.
- HollowGraph also uses DNS tunneling through cloudlanecdn[.]com to refresh Entra ID configuration data.
- Group-IB links the activity to the Cavern framework and suspects an Iranian-nexus operation focused on Israel.