The HOLLOWGRAPH espionage campaign utilizes a .NET DLL implant to establish stealthy command-and-control (C2) by abusing the Microsoft Graph API. The malware hijacks compromised Microsoft 365 mailboxes, using calendar appointments specifically dated to May 13, 2050, as dead-drop resolvers for operator instructions and data exfiltration. By routing traffic through legitimate Microsoft cloud infrastructure, the operation bypasses traditional network monitoring and avoids the use of attacker-controlled infrastructure. Linked to the Cavern C2 framework and suspected Iranian-nexus actors (Lyceum), the campaign has primarily targeted entities in Israel; no patch is available as it leverages legitimate platform functionality.
-
Incident Overview: Targeted Espionage
- Sophisticated espionage operation focused on high-value targets within Israel.
- Deployment of HOLLOWGRAPH, a specialized .NET DLL implant.
- Group-IB researchers have identified at least 12 infected systems to date.
-
Attack Vector & C2 Mechanics: Graph API Abuse
- Leverages the Microsoft Graph API to blend malicious activity with routine business traffic.
- Employs Microsoft 365 calendar events as a bidirectional "dead drop" for C2 communication.
- Operator instructions and exfiltrated files are stored within calendar entries specifically dated to May 13, 2050.
- Utilizes OAuth2 and Entra ID exploitation to maintain persistent access to target environments.
-
Stealth & Evasion Techniques: Living off the Cloud
- Eliminates the need for traditional attacker-owned C2 servers, removing a primary indicator for network defense.
- Future-dating calendar entries hides data from standard administrative views and manual audits.
- Traffic remains indistinguishable from legitimate Outlook and Microsoft 365 cloud communication.
-
Threat Actor Profile: Cavern & Lyceum
- High-confidence link to the Cavern backdoor framework.
- Low-to-moderate confidence attribution to Lyceum, a suspected Iranian-nexus threat group.
- Focus on strategic intelligence gathering within the Israeli geography.
-
Defensive Challenges & Mitigation
- Mitigation is high-difficulty because the attack abuses native cloud features rather than software vulnerabilities.
- Traditional IP-based blocking is ineffective as all traffic targets legitimate Microsoft endpoints.
- Detection requires deep inspection of Graph API call patterns and auditing for anomalous future-dated calendar events.
Related posts
- malware-log.hatenablog.com — HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050
- The Register - Security — Microsoft 365 calendars become spy drop boxes in HOLLOWGRAPH campaign
- helpnetsecurity.com — HOLLOWGRAPH malware turns Microsoft 365 calendars into an espionage channel
- simplysecuregroup.com — New HollowGraph malware uses Microsoft Graph for stealthy C2 comms
- datawater.com — HollowGraph: Espionage Malware Hides C2 in Microsoft 365 Calendar Events Dated 2050 — No Attacker Server, No Patch, Traffic Indistinguishable from Outlook
- simplysecuregroup.com — Hackers Hide Malware Commands in Outlook Events Dated 2050 and Use as C2 Channel
- Cybersecurity News — Hackers Hide Malware Commands in Outlook Events Dated 2050 and Use as C2 Channel
- gbhackers.com — New CAV3RN Module Replaces WebSocket C2 With Outlook Calendar Dead Drops
- SecurityWeek — New HollowGraph Malware Abuses Microsoft 365 Calendar for C&C Communication
- feeds.feedburner.com — HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050
- Itsecurityguru
- Securityonline
- Itbranschen
- Group-ib
- Scworld
- Infosecurity-magazine
- Kordon
- Medium
- Ground
- Techradar