HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050
ID: 0a1cb597-1b47-5974-b972-d288af489866
STIX ID: report--0a1cb597-1b47-5974-b972-d288af489866
Feed Name: The Hacker News
**HollowGraph** is a .NET espionage implant that abuses Microsoft 365 calendars and the Graph API as a stealthy two-way dead-drop: it reads operator tasking from far-future events (notably dated `2050-05-13`) and exfiltrates stolen files as encrypted attachments, while a secondary DNS AAAA channel returns tenant/client credentials (written to `logAzure.txt`). Group-IB links the tool to the Cavern/Cavern Manticore ecosystem, found on at least 12 hosts with active traffic between 3 June and 9 July 2026, and provides IOCs and detection guidance focused on far-future calendar events, GUID-like subjects, `File{n}.txt` attachments, `cloudlanecdn.com`, and audit of app client credentials and Graph-driven calendar changes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
