← Back to Daily Briefing

The HOLLOWGRAPH espionage campaign utilizes a .NET DLL implant to establish stealthy command-and-control (C2) by abusing the Microsoft Graph API. The malware hijacks compromised Microsoft 365 mailboxes, using calendar appointments specifically dated to May 13, 2050, as dead-drop resolvers for operator instructions and data exfiltration. By routing traffic through legitimate Microsoft cloud infrastructure, the operation bypasses traditional network monitoring and avoids the use of attacker-controlled infrastructure. Linked to the Cavern C2 framework and suspected Iranian-nexus actors (Lyceum), the campaign has primarily targeted entities in Israel; no patch is available as it leverages legitimate platform functionality.

  • Incident Overview: Targeted Espionage

    • Sophisticated espionage operation focused on high-value targets within Israel.
    • Deployment of HOLLOWGRAPH, a specialized .NET DLL implant.
    • Group-IB researchers have identified at least 12 infected systems to date.
  • Attack Vector & C2 Mechanics: Graph API Abuse

    • Leverages the Microsoft Graph API to blend malicious activity with routine business traffic.
    • Employs Microsoft 365 calendar events as a bidirectional "dead drop" for C2 communication.
    • Operator instructions and exfiltrated files are stored within calendar entries specifically dated to May 13, 2050.
    • Utilizes OAuth2 and Entra ID exploitation to maintain persistent access to target environments.
  • Stealth & Evasion Techniques: Living off the Cloud

    • Eliminates the need for traditional attacker-owned C2 servers, removing a primary indicator for network defense.
    • Future-dating calendar entries hides data from standard administrative views and manual audits.
    • Traffic remains indistinguishable from legitimate Outlook and Microsoft 365 cloud communication.
  • Threat Actor Profile: Cavern & Lyceum

    • High-confidence link to the Cavern backdoor framework.
    • Low-to-moderate confidence attribution to Lyceum, a suspected Iranian-nexus threat group.
    • Focus on strategic intelligence gathering within the Israeli geography.
  • Defensive Challenges & Mitigation

    • Mitigation is high-difficulty because the attack abuses native cloud features rather than software vulnerabilities.
    • Traditional IP-based blocking is ineffective as all traffic targets legitimate Microsoft endpoints.
    • Detection requires deep inspection of Graph API call patterns and auditing for anomalous future-dated calendar events.

Related posts

  1. malware-log.hatenablog.com — HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050
  2. The Register - Security — Microsoft 365 calendars become spy drop boxes in HOLLOWGRAPH campaign
  3. helpnetsecurity.com — HOLLOWGRAPH malware turns Microsoft 365 calendars into an espionage channel
  4. simplysecuregroup.com — New HollowGraph malware uses Microsoft Graph for stealthy C2 comms
  5. datawater.com — HollowGraph: Espionage Malware Hides C2 in Microsoft 365 Calendar Events Dated 2050 — No Attacker Server, No Patch, Traffic Indistinguishable from Outlook
  6. simplysecuregroup.com — Hackers Hide Malware Commands in Outlook Events Dated 2050 and Use as C2 Channel
  7. Cybersecurity News — Hackers Hide Malware Commands in Outlook Events Dated 2050 and Use as C2 Channel
  8. gbhackers.com — New CAV3RN Module Replaces WebSocket C2 With Outlook Calendar Dead Drops
  9. SecurityWeek — New HollowGraph Malware Abuses Microsoft 365 Calendar for C&C Communication
  10. feeds.feedburner.com — HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050
  11. Itsecurityguru
  12. Securityonline
  13. Itbranschen
  14. Group-ib
  15. Reddit
  16. Scworld
  17. Infosecurity-magazine
  18. Kordon
  19. Medium
  20. Ground
  21. Techradar

LINK COPIED TO CLIPBOARD