HOLLOWGRAPH Campaign Abuses Microsoft 365 Graph API for Stealthy C2
The HOLLOWGRAPH espionage campaign utilizes a .NET DLL implant to establish stealthy command-and-control (C2) by abusing the Microsoft Graph API. The malware hijacks compromised Microsoft 365 mailboxes, using calendar appointments specifically dated to May 13, 2050, as dead-drop resolvers for operator instructions and data exfiltration. By routing traffic through legitimate Microsoft cloud infrastructure, the operation bypasses traditional network monitoring and avoids the use of attacker-controlled infrastructure. Linked to the Cavern C2 framework and suspected Iranian-nexus actors (Lyceum), the campaign has primarily targeted entities in Israel; no patch is available as it leverages legitimate platform functionality.
Cavern Manticore Exploiting SysAid via Modular Cavern C2 Framework
Iranian state-sponsored threat actor Cavern Manticore, linked to the Ministry of Intelligence and Security (MOIS), has executed a targeted campaign against Israeli government agencies and IT service providers. The intrusion leverages a supply chain compromise of the SysAid software platform to achieve initial access. Following exploitation, the actor deploys the "Cavern" (Cav3rn) framework, a modular and highly adaptable command-and-control (C2) architecture designed for deep reconnaissance and data exfiltration. This campaign demonstrates advanced tactical continuity with established Iranian APTs, specifically MuddyWater and Lyceum, utilizing specialized modular tasking to maintain persistence and navigate high-value environments.