logo

HOLLOWGRAPH Malware Turns Microsoft 365 Calendar Events Into Covert Command-and-Control Channels

ID: d8b15c32-363c-57c1-b06d-65d9716f1c6c

STIX ID: report--d8b15c32-363c-57c1-b06d-65d9716f1c6c

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-07-21

Date Updated: 2026-07-21

Author: Divya

...
...

HOLLOWGRAPH is a sophisticated Windows implant that leverages Microsoft Graph calendar events as a two‑way covert C2/exfiltration channel and uses IPv6 AAAA DNS tunneling to refresh Microsoft Entra ID credentials. Compiled as a .NET NativeAOT DLL, it supports encrypted “get” and “send” commands, hybrid RSA-OAEP/AES-256-GCM cryptography, and schedules far-future calendar events to hide activity; Group-IB observed ~12 infected systems (about three active) between June 3 and July 9, 2026, with evidence suggesting targeted espionage against Israeli organizations. The report includes hashes for detection, recommends auditing Graph API calendar activity and anomalous AAAA DNS queries, and urges immediate rotation of exposed Entra ID credentials.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.