CyberSecurity SEE

New HollowGraph Malware Takes Control of Microsoft 365 Calendars for Covert Command and Control

New HollowGraph Malware Takes Control of Microsoft 365 Calendars for Covert Command and Control

Malware Exploits Microsoft Graph API for Covert Operations

In a recent discovery by cybersecurity researchers at Group-IB, a newly identified Windows malware sample has emerged that effectively exploits the Microsoft Graph API. This malware takes advantage of compromised Microsoft 365 calendars to create a covert two-way command and control (C2) channel, making it significantly challenging to detect and counteract.

The researchers have named this sophisticated malware “HollowGraph” and have attributed it, with high confidence, to the well-known Cavern backdoor framework. Their analysis revealed that the attacks initiated by HollowGraph are highly targeted, focusing specifically on entities within Israel. This focus is substantiated by the identification of a compromised mailbox linked to an Israeli organization.

Intriguingly, the malware files involved in the attack were also traced back to Israel. Additionally, the files associated with the broader Cavern framework were found to originate from the same country. This evidence strongly accentuates the operation’s target profile.

Group-IB reported that they identified 12 systems infected with the HollowGraph malware, with the earliest recorded communication between a victim and the attacker occurring on June 3, 2026. The most recent example of this malicious activity was observed on July 9. The researchers noted that the relatively small number of victims suggests a highly targeted operation rather than a scattered, opportunistic approach.

In their findings, Group-IB acknowledged the challenges in confidently attributing the malware to any previously recognized threat actor. However, they did identify notable technical similarities with the Iranian-affiliated threat actor known as Lyceum, which is known for its espousal of espionage activities. This linkage underscores the sophistication of the malware and the targeted nature of its deployment.

“The sophistication of the malware, coupled with the disciplined and narrowly scoped targeting of Israeli entities, indicates a capable and well-resourced adversary,” stated the researchers. This position highlights the growing concern surrounding specialized malware that can carry out highly precise attacks.

Utilizing Trusted Infrastructure for Evasion

The HollowGraph malware operates with two primary commands: "get" and "send." Crucially, it relies exclusively on trusted third-party infrastructures for its communication, thus avoiding direct interactions with servers owned by the attackers for its payload delivery. This complexity adds an additional layer of stealth to its operations.

Specifically, the "send" command has the capability to create calendar appointments containing encrypted files that have been stolen, attaching them in a way that is hard to detect. Conversely, the "get" command is used to search for these appointments and download the instructions hidden within the attachments.

Notably, HollowGraph employs DNS tunneling to disseminate and refresh Microsoft Entra ID (Azure AD) credentials. These credentials are essential for authenticating communications through the Graph channel, which, while effective, is not encrypted. In terms of encryption, HollowGraph utilizes a sophisticated hybrid scheme combining RSA and AES-256-GCM algorithms, ensuring the security of Graph communications. Each direction (inbound and outbound) uses distinct RSA key pairs, a feature noted in Group-IB’s research.

Connection to the Cavern Framework

Group-IB has established several technical characteristics linking HollowGraph to the Cavern framework. A key indicator lies in the command format, which is similar to that of Cavern. The malicious commands are invoked through a specific string format that matches the syntax used in Cavern operations, thereby reinforcing Group-IB’s claim.

One command, “MzU=,” decodes to "003", which corresponds to a toggle debug logging instruction identified as an agent self-command within the Cavern ecosystem. The observed tasking format, too, mirrors that of Cavern, highlighting the consistent operational structure.

According to these findings, Group-IB has assessed that HollowGraph represents a distinct variant within the Cavern framework, raising alarms about the capabilities of those behind this malware.

In light of these developments, Group-IB has advised organizations to remain vigilant. They recommend continuous monitoring for indicators associated with HollowGraph and increased surveillance of Microsoft Graph API activities. Particular attention should be given to Microsoft 365 mailbox audits to detect any anomalous calendar operations, including unexpected event creation, file attachment uploads, and subject changes performed by applications instead of end-users. Such proactive measures are essential to counter the subtle yet dangerously persistent threats posed by sophisticated malware like HollowGraph.

Source link

Exit mobile version