FILTERING BY: CLEAR FILTER

HOLLOWGRAPH Espionage Campaign Exploits Microsoft 365 Calendar via Graph API

HOLLOWGRAPH is a sophisticated .NET DLL-based espionage implant that leverages the Microsoft Graph API to establish a two-way Command and Control (C2) channel through legitimate Microsoft 365 calendar events. By utilizing the user's calendar as a "dead drop," the malware hides operator instructions and exfiltrated data within appointments and attachments specifically dated for May 13, 2050. This technique bypasses traditional network security perimeters by masquerading as authorized cloud synchronization traffic, making the malicious activity indistinguishable from standard Microsoft 365 operations. The campaign has been identified targeting Israeli entities, with high-confidence associations to the Cavern modular framework.


LINK COPIED TO CLIPBOARD