Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

US Hospital Finance Software Provider Craneware Reports Data Theft

July 21, 2026

Two SonicWall SMA 1000 Zero-Days Exploited, One Could Enable Admin Commands

July 21, 2026

Microsoft Patches Record 622 Flaws, Including Two Zero-Days Under Active Attack

July 21, 2026
Facebook X (Twitter) Instagram
Tuesday, July 21
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»New HollowGraph Malware Hijacks Microsoft 365 Calendars for Covert C2
News

New HollowGraph Malware Hijacks Microsoft 365 Calendars for Covert C2

Team-CWDBy Team-CWDJuly 20, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


A newly identified Windows malware sample abuses Microsoft Graph API to transform a compromised Microsoft 365 calendar into a covert two-way command and control (C2) channel.

Researchers at Group-IB dubbed the highly sophisticated malware sample HollowGraph and attributed it, with high confidence, to the Cavern backdoor framework. 

Analysis by Group-IB found that the HollowGraph attack is highly targeted and focuses on Israeli entities. This is because the compromised mailbox identified was associated with an Israeli organization.

In addition, the malware files uploaded were from Israel and files associated with the broader Cavern framework were also uploaded from Israel.

Group-IB said it identified 12 systems infected with the HollowGraph malware and earliest observed communication between a victim and attacker occurred on June 3, 2026. The most recent example was identified on July 9.

“The relatively small number of identified victims suggests that the operation is highly targeted rather than opportunistic,” the researchers said in a July 20 post.

While the firm could not confidently attribute to any previously identified threat actor, researchers identified several technical similarities with the Iranian-nexus threat actor Lyceum for espionage activities.

“The sophistication of the malware, combined with the disciplined, narrowly scoped targeting of Israeli entities, points to a capable and well-resourced adversary,” the researchers said.

HollowGraph Uses Trusted Microsoft Services to Evade Detection

The malware supports two commands, get and send, and relies entirely on trusted third-party infrastructure for communication, never reaching out directly to attacker-owned servers for payload delivery.

The send command generates calendar appointments with encrypted stolen files attached.

Meanwhile, the get command searches for appointments planted by the operator and downloads the attached instructions.

HollowGraph also uses DNS tunneling to deliver and refresh Microsoft Entra ID (Azure AD) credentials needed to authenticate to the Graph channel. This channel is not encrypted.

For encryption it uses a hybrid scheme com RSA and AES-256-GCM secures Graph communications, with distinct RSA key pairs used for each direction (inbound vs. outbound), according to Group-IB research.

On its link to the Cavern framework, Group-IB said several technical characteristics strongly suggest HollowGraph is part of this and the broader toolkit.

Among these characteristics are the command format. The component is invoked with the string format _;;__,__,_, which matches Cavern’s command syntax.

The attackers issued commands including MzU=, which decodes to 003, a Toggle debug logging instruction command classified as an agent self command for the Cavern malware.

Finally, it has a matching command structure from the C2 server. The observed tasking mirrors Cavern’s format, e.g. {“cid”: “oXhLaJ0ZvtPb9XB”, “type”: “self”, “cmd”: “003_;;__,_”}

These technical details have led Group-IB to assess that HollowGraph is part of a different variant of the Cavern framework.

The cybersecurity firm recommended organizations to continuously hunt for indicators associated with HollowGraph and to monitor Microsoft Graph API activity and Microsoft 365 mailbox audit for anomalous calendar operations. Such operations include event creation, attachment uploads and subject changes performed by an application rather than a user.



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleSAP Patches CVSS 9.9 NetWeaver ABAP Flaw That Could Expose or Modify Data
Next Article From FBI Cybercrime to Barbie’s CISO: a Leadership Story
Team-CWD
  • Website

Related Posts

News

US Hospital Finance Software Provider Craneware Reports Data Theft

July 21, 2026
News

Two SonicWall SMA 1000 Zero-Days Exploited, One Could Enable Admin Commands

July 21, 2026
News

Microsoft Patches Record 622 Flaws, Including Two Zero-Days Under Active Attack

July 21, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

Cyber M&A Roundup: Cyber Giants Strengthen AI Security Offerings

December 1, 20258 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

Children and chatbots: What parents should know

January 23, 2026

How it preys on personal data – and how to stay safe

October 23, 2025

Chronology of a Skype attack

February 5, 2026

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.