defense · BleepingComputer
HollowGraph, a malicious module analyzed by Group-IB, leverages the calendar feature in compromised Microsoft 365 mailboxes to establish command-and-control communications. The malware authenticates to Microsoft Graph API using hardcoded credentials stored in a configuration file disguised as logAzure.txt, then creates calendar events dated May 13, 2050, to conceal commands and exfiltrated data within attachments. At least 12 systems have been infected, with three actively communicating with the threat actor between June 3 and July 9. Researchers assess with high confidence that HollowGraph is associated with the Cavern C2 framework and observe technical similarities to the Iranian-nexus threat actor Lyceum, though definitive attribution remains uncertain. The campaign appears targeted at organizations in Israel for espionage purposes.
Organizations using Microsoft 365—especially defense contractors managing Controlled Unclassified Information (CUI) under CMMC requirements and SaaS teams in SOC2 Type II audits—should heighten monitoring of OAuth client-credential flows and calendar activity within cloud environments. The use of trusted Microsoft infrastructure to hide malicious traffic exemplifies how threat actors bypass perimeter controls, making cloud audit logging and Conditional Access policies critical controls. Healthcare providers and fintechs subject to HIPAA and PCI DSS must similarly treat cloud mailbox abuse as a data exfiltration vector. An Omniware engagement can scope detection strategies, OAuth governance baselines, and incident response playbooks for cloud-based C2 activity.
Source: BleepingComputer - https://www.bleepingcomputer.com/news/security/new-hollowgraph-malware-uses-microsoft-graph-for-stealthy-c2-comms/
Source: BleepingComputer
All briefings