Hackers Are Turning Microsoft 365 Calendar Invites Into Secret Malware Command Channels
ID: 266509f2-df3d-583e-bfd6-d938b0e3e855
STIX ID: report--266509f2-df3d-583e-bfd6-d938b0e3e855
Feed Name: cybersecurityNews.com
A Group-IB report details HOLLOWGRAPH, a .NET malware that hijacks Microsoft 365 calendars via the Microsoft Graph API to receive commands and exfiltrate encrypted data inside calendar event attachments, while using IPv6 AAAA DNS queries to cloudlanecdn.com to refresh Entra ID credentials saved to a disguised logAzure.txt file. The operators schedule malicious events for May 13, 2050 to avoid user notice; activity (12 infected hosts, ~3 actively communicating) was observed June–July 2026 and appears focused on Israeli organizations. Group-IB links HOLLOWGRAPH to the Cavern backdoor/Cavern Manticore framework (high confidence), notes low-confidence overlaps with Lyceum/OilRig, and provides IoCs (event naming patterns, File{n}.txt attachments, cloudlanecdn.com, logAzure.txt, unusual AAAA queries) plus detection and mitigation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
