logo

HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050

ID: 0a1cb597-1b47-5974-b972-d288af489866

STIX ID: report--0a1cb597-1b47-5974-b972-d288af489866

Feed Name: The Hacker News

Threat Score
78/100

Date Published: 2026-07-20

Date Updated: 2026-07-20

Author: [email protected] (The Hacker News)

...
...

**HollowGraph** is a .NET espionage implant that abuses Microsoft 365 calendars and the Graph API as a stealthy two-way dead-drop: it reads operator tasking from far-future events (notably dated `2050-05-13`) and exfiltrates stolen files as encrypted attachments, while a secondary DNS AAAA channel returns tenant/client credentials (written to `logAzure.txt`). Group-IB links the tool to the Cavern/Cavern Manticore ecosystem, found on at least 12 hosts with active traffic between 3 June and 9 July 2026, and provides IOCs and detection guidance focused on far-future calendar events, GUID-like subjects, `File{n}.txt` attachments, `cloudlanecdn.com`, and audit of app client credentials and Graph-driven calendar changes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.