New HollowGraph Malware Hijacks Microsoft 365 Calendars for Covert C2 Communications
ID: 9da25b1b-09f8-5dd0-80cc-593aa14486d6
STIX ID: report--9da25b1b-09f8-5dd0-80cc-593aa14486d6
Feed Name: Infosecurity Magazine (News)
Researchers at Group-IB identified a sophisticated Windows malware called HollowGraph that uses Microsoft Graph API and Microsoft 365 calendar appointments (attachments) to implement a covert two-way C2 channel, delivering and receiving encrypted payloads and instructions; it also uses DNS tunneling to manage Azure AD credentials. The activity, linked by technical indicators to the Cavern framework and displaying similarities to the Lyceum actor, appears highly targeted at Israeli organizations with 12 infected systems observed between June 3 and July 9, 2026, prompting recommendations to monitor Graph API and mailbox calendar operations for anomalies.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
