HOLLOWGRAPH: Turning Microsoft 365 Calendars into Covert Command-and-Control Channels
ID: 995ed95e-d738-5713-9283-bbe8cfa657fe
STIX ID: report--995ed95e-d738-5713-9283-bbe8cfa657fe
Feed Name: Group-IB Blog
Threat Score
Group-IB describes HOLLOWGRAPH, an advanced, targeted espionage malware that abuses Microsoft Graph calendar events for covert C2 and exfiltration (events dated 2050 with File{n}.txt attachments) and uses DNS AAAA tunneling to refresh Azure AD credentials; the report includes technical details, hybrid RSA+AES encryption usage, on-disk configuration (logAzure.txt), IOCs, and linkage to the Cavern framework with targeting focused on Israeli entities.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
