FILTERING BY: CLEAR FILTER

HOLLOWGRAPH Espionage Campaign Exploits Microsoft 365 Calendar via Graph API

HOLLOWGRAPH is a sophisticated .NET DLL-based espionage implant that leverages the Microsoft Graph API to establish a two-way Command and Control (C2) channel through legitimate Microsoft 365 calendar events. By utilizing the user's calendar as a "dead drop," the malware hides operator instructions and exfiltrated data within appointments and attachments specifically dated for May 13, 2050. This technique bypasses traditional network security perimeters by masquerading as authorized cloud synchronization traffic, making the malicious activity indistinguishable from standard Microsoft 365 operations. The campaign has been identified targeting Israeli entities, with high-confidence associations to the Cavern modular framework.

Cavern Manticore Exploiting SysAid via Modular Cavern C2 Framework

Iranian state-sponsored threat actor Cavern Manticore, linked to the Ministry of Intelligence and Security (MOIS), has executed a targeted campaign against Israeli government agencies and IT service providers. The intrusion leverages a supply chain compromise of the SysAid software platform to achieve initial access. Following exploitation, the actor deploys the "Cavern" (Cav3rn) framework, a modular and highly adaptable command-and-control (C2) architecture designed for deep reconnaissance and data exfiltration. This campaign demonstrates advanced tactical continuity with established Iranian APTs, specifically MuddyWater and Lyceum, utilizing specialized modular tasking to maintain persistence and navigate high-value environments.


LINK COPIED TO CLIPBOARD