logo

HOLLOWGRAPH: Turning Microsoft 365 Calendars into Covert Command-and-Control Channels

ID: 995ed95e-d738-5713-9283-bbe8cfa657fe

STIX ID: report--995ed95e-d738-5713-9283-bbe8cfa657fe

Feed Name: Group-IB Blog

Threat Score
75/100

Date Published: 2026-07-20

Date Updated: 2026-07-20

...
...

Group-IB describes HOLLOWGRAPH, an advanced, targeted espionage malware that abuses Microsoft Graph calendar events for covert C2 and exfiltration (events dated 2050 with File{n}.txt attachments) and uses DNS AAAA tunneling to refresh Azure AD credentials; the report includes technical details, hybrid RSA+AES encryption usage, on-disk configuration (logAzure.txt), IOCs, and linkage to the Cavern framework with targeting focused on Israeli entities.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.