Group-IB has discovered a new espionage implant named HollowGraph that hijacks Microsoft 365 calendars for command-and-control (C2) and data exfiltration. The malware, a .NET DLL, uses calendar events dated to the year 2050 to hide operator instructions and stolen files, leveraging legitimate Microsoft Graph API traffic to evade detection. It supports only two commands—get and send—and never contacts attacker-owned servers. Instead, it queries a compromised mailbox’s calendar for events planted by the operator, reading instructions from attached files, and exfiltrates data by creating its own far-future events with encrypted attachments. A secondary DNS channel refreshes Entra ID credentials via IPv6 AAAA records from the domain cloudlanecdn[.]com, storing them in a file named logAzure.txt. Group-IB links HollowGraph to the Cavern backdoor framework with high confidence, but cannot attribute the campaign to a specific threat actor, noting only a low-confidence overlap with Lyceum (a subgroup of OilRig). The implant was found on at least 12 machines, with active victim traffic from June 3 to July 9, 2026, targeting an Israeli organization. No Microsoft vulnerability is exploited; the attack relies on compromised accounts and Graph API functionality. Detection advice includes monitoring for calendar events with far-future dates (2050-05-13), GUID subjects, or attachments named File{n}.txt, as well as auditing OAuth app permissions and DNS queries for cloudlanecdn[.]com.
Attack groups: Cavern Manticore, MuddyWater, Lyceum, OilRig
Malware: HollowGraph, Cavern
Companies: Group-IB, Check Point, Microsoft
Products: Microsoft 365, Microsoft Graph API, Entra ID
Original source: thehackernews.com