malware-log.hatenablog.com • 2h
HOLLOWGRAPH Campaign Abuses Microsoft 365 Graph API for Stealthy C2
The HOLLOWGRAPH espionage campaign utilizes a .NET DLL implant to establish stealthy command-and-control (C2) by abusing the Microsoft Graph API. The malware hijacks compromised Microsoft 365 mailboxes, using calendar appointments specifically dated to May 13, 2050, as dead-drop resolvers for operator instructions and data exfiltration. By routing traffic through legitimate Microsoft cloud infrastructure, the operation bypasses traditional network monitoring and avoids the use of attacker-controlled infrastructure. Linked to the Cavern C2 framework and suspected Iranian-nexus actors (Lyceum), the campaign has primarily targeted entities in Israel; no patch is available as it leverages legitimate platform functionality.