HOLLOWGRAPH Backdoor Turns Microsoft 365 Calendars Into a C2 Channel
ID: 7c2214f9-91c1-5dd0-9b41-994bd0b77012
STIX ID: report--7c2214f9-91c1-5dd0-9b41-994bd0b77012
Feed Name: Picus Security Articles
HOLLOWGRAPH is a Windows espionage backdoor distributed as a .NET NativeAOT DLL masquerading as a Brotli library that avoids traditional C2 by abusing a compromised Microsoft 365 mailbox calendar as a dead-drop (operator tasking via calendar event attachments and exfiltration via encrypted attachments). It uses RSA-OAEP and AES-256-GCM with directional key separation, and maintains access by pulling refreshed Entra ID credentials via DNS AAAA queries to an attacker-controlled domain; the report includes operational details, example Graph API calls, the DNS chunking scheme, and guidance to simulate the attack with the Picus Platform.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
