malware-log.hatenablog.com • 6w
HOLLOWGRAPH Campaign Abuses Microsoft 365 Graph API for Stealthy C2
The HOLLOWGRAPH espionage campaign utilizes a .NET DLL implant to establish stealthy command-and-control (C2) by abusing the Microsoft Graph API. The malware hijacks compromised Microsoft 365 mailboxes, using calendar appointments specifically dated to May 13, 2050, as dead-drop resolvers for operator instructions and data exfiltration. By routing traffic through legitimate Microsoft cloud infrastructure, the operation bypasses traditional network monitoring and avoids the use of attacker-controlled infrastructure. Linked to the Cavern C2 framework and suspected Iranian-nexus actors (Lyceum), the campaign has primarily targeted entities in Israel; no patch is available as it leverages legitimate platform functionality.
Links:malware-log.hatenablog.com, The Register - Security, helpnetsecurity.com, simplysecuregroup.com, datawater.com, Cybersecurity News, gbhackers.com, SecurityWeek, feeds.feedburner.com, Itsecurityguru, Securityonline, Itbranschen, Group-ib, Reddit, Scworld, Infosecurity-magazine, Kordon, Medium, Ground, Techradar •