HOLLOWGRAPH is a sophisticated .NET DLL-based espionage implant that leverages the Microsoft Graph API to establish a two-way Command and Control (C2) channel through legitimate Microsoft 365 calendar events. By utilizing the user's calendar as a "dead drop," the malware hides operator instructions and exfiltrated data within appointments and attachments specifically dated for May 13, 2050. This technique bypasses traditional network security perimeters by masquerading as authorized cloud synchronization traffic, making the malicious activity indistinguishable from standard Microsoft 365 operations. The campaign has been identified targeting Israeli entities, with high-confidence associations to the Cavern modular framework.
-
Incident Overview
- Discovery of HOLLOWGRAPH by Group-IB during investigations into targeted espionage.
- Deployment of .NET DLL implants designed for persistent, stealthy data exfiltration.
- High-confidence link to the Cavern modular backdoor framework.
- Potential low-confidence attribution to the Lyceum threat actor (Iranian-nexus).
-
Attack Vector & C2 Mechanics
- Exploitation of the Microsoft Graph API to interact directly with compromised M365 accounts.
- Utilization of the Microsoft 365 Calendar as a "dead drop" for two-way communication.
- Command and control traffic is tunneled through legitimate, encrypted Microsoft cloud traffic.
- Circumvention of traditional IP-based reputation filtering and domain blacklisting.
-
Evasion & Obfuscation Techniques
- Storage of C2 instructions and stolen intelligence within calendar appointment bodies.
- Use of specific temporal markers, specifically May 13, 2050, to isolate malicious data.
- Obfuscation of exfiltrated files within legitimate calendar attachments.
- Integration of malicious activity into routine, authorized cloud synchronization patterns.
-
Impact & Scale
- Primary targeting observed against Israeli entities and organizations.
- Initial detection scale identified at 12 infected systems by Group-IB.
- Universal risk profile: the technique is reusable against any organization using Microsoft 365.
- Zero-patch requirement: the threat exploits legitimate cloud functionality rather than software vulnerabilities.
-
Defensive Implications
- Necessity for advanced monitoring of Microsoft Graph API call patterns and volumes.
- Implementation of detection logic for anomalous calendar metadata (e.g., far-future dates).
- Requirement for identity-centric security models to detect unauthorized API usage.
- Traditional network-layer inspection is largely ineffective against this cloud-native C2.
Related posts
- The Register - Security — Microsoft 365 calendars become spy drop boxes in HOLLOWGRAPH campaign
- helpnetsecurity.com — HOLLOWGRAPH malware turns Microsoft 365 calendars into an espionage channel
- datawater.com — HollowGraph: Espionage Malware Hides C2 in Microsoft 365 Calendar Events Dated 2050 — No Attacker Server, No Patch, Traffic Indistinguishable from Outlook
- feeds.feedburner.com — HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050
- Itsecurityguru
- Securityonline
- Itbranschen
- Group-ib
- Scworld
- Infosecurity-magazine