HOLLOWGRAPH is a newly identified Windows espionage malware that transforms a compromised Microsoft 365 environment into a covert command-and-control (C2) platform. Rather than relying on attacker-controlled servers, the malware abuses the Microsoft Graph API to communicate through a victim's Microsoft 365 calendar, allowing malicious traffic to blend seamlessly with legitimate cloud activity. Attackers issue commands by creating calendar events, while the malware exfiltrates stolen files by uploading encrypted attachments to newly created events. To avoid detection by users, all malicious calendar entries are scheduled far into the future, specifically in the year 2050. HOLLOWGRAPH also maintains persistence by refreshing its Microsoft Entra ID (Azure AD) credentials through DNS tunneling, enabling continued access even if credentials change. The malware has been linked with high confidence to the Cavern backdoor framework based on shared command structures and operational characteristics, although attribution to a specific threat actor remains inconclusive. Researchers identified at least 12 compromised systems, with evidence indicating a highly targeted cyber espionage campaign primarily focused on Israeli organizations rather than indiscriminate, large-scale attacks.
HOLLOWGRAPH is implemented as a .NET NativeAOT-compiled DLL and is designed around a minimal yet effective command set consisting of only get and send operations. The malware uses the Microsoft Graph API as its primary communication channel, treating a compromised Microsoft 365 calendar as a dead-drop repository where attackers hide encrypted instructions inside calendar events and retrieve exfiltrated data from event attachments. Every malicious event is timestamped for May 2050, reducing the likelihood of user discovery. To protect communications, HOLLOWGRAPH employs hybrid cryptography, combining RSA-OAEP and AES-256-GCM with separate key pairs for inbound tasking and outbound data exfiltration. A secondary DNS tunneling channel periodically retrieves updated Microsoft Entra ID credentials by encoding configuration data within IPv6 AAAA DNS responses from an attacker-controlled domain. The malware stores configuration details, including tenant identifiers, application credentials, mailbox information, and cryptographic keys, in a local file named logAzure.txt. Analysis also revealed command syntax and communication patterns closely matching the Cavern framework, indicating that HOLLOWGRAPH is likely part of a larger modular cyber espionage toolkit.[/subscribe_to_unlock_form]
HOLLOWGRAPH is a newly identified Windows espionage malware that transforms a compromised Microsoft 365 environment into a covert command-and-control (C2) platform. Rather than relying on attacker-controlled servers, the malware abuses the Microsoft Graph API to communicate through a victim's Microsoft 365 calendar, allowing malicious traffic to blend seamlessly with legitimate cloud activity. Attackers issue commands by creating calendar events, while the malware exfiltrates stolen files by uploading encrypted attachments to newly created events. To avoid detection by users, all malicious calendar entries are scheduled far into the future, specifically in the year 2050. HOLLOWGRAPH also maintains persistence by refreshing its Microsoft Entra ID (Azure AD) credentials through DNS tunneling, enabling continued access even if credentials change. The malware has been linked with high confidence to the Cavern backdoor framework based on shared command structures and operational characteristics, although attribution to a specific threat actor remains inconclusive. Researchers identified at least 12 compromised systems, with evidence indicating a highly targeted cyber espionage campaign primarily focused on Israeli organizations rather than indiscriminate, large-scale attacks.
HOLLOWGRAPH is implemented as a .NET NativeAOT-compiled DLL and is designed around a minimal yet effective command set consisting of only get and send operations. The malware uses the Microsoft Graph API as its primary communication channel, treating a compromised Microsoft 365 calendar as a dead-drop repository where attackers hide encrypted instructions inside calendar events and retrieve exfiltrated data from event attachments. Every malicious event is timestamped for May 2050, reducing the likelihood of user discovery. To protect communications, HOLLOWGRAPH employs hybrid cryptography, combining RSA-OAEP and AES-256-GCM with separate key pairs for inbound tasking and outbound data exfiltration. A secondary DNS tunneling channel periodically retrieves updated Microsoft Entra ID credentials by encoding configuration data within IPv6 AAAA DNS responses from an attacker-controlled domain. The malware stores configuration details, including tenant identifiers, application credentials, mailbox information, and cryptographic keys, in a local file named logAzure.txt. Analysis also revealed command syntax and communication patterns closely matching the Cavern framework, indicating that HOLLOWGRAPH is likely part of a larger modular cyber espionage toolkit.[emaillocker id="1283"]
HOLLOWGRAPH demonstrates the growing sophistication of modern cyber espionage operations by exploiting trusted cloud services instead of traditional attacker-controlled infrastructure. By leveraging Microsoft Graph API and legitimate Microsoft 365 calendar functionality, the malware effectively disguises malicious communications as normal enterprise cloud traffic, significantly reducing the effectiveness of conventional network-based detection mechanisms. Its additional use of DNS tunneling for credential renewal, strong hybrid encryption, and narrowly focused victim selection reflects a mature and well-resourced adversary with advanced operational security practices. Although the malware has been associated with the Cavern framework and shows similarities to activity previously linked to Iranian-aligned operations, current evidence is insufficient for definitive attribution to any known threat actor. The campaign appears highly selective, targeting a limited number of Israeli entities rather than conducting broad opportunistic attacks, indicating an intelligence-gathering objective. The discovery highlights the increasing abuse of trusted SaaS platforms as covert communication channels and emphasizes the need for organizations to monitor Microsoft Graph API activity, abnormal calendar operations, cloud identity usage, and DNS anomalies to detect advanced threats that intentionally blend into legitimate enterprise environments.
| Tactic | Technique Id | Technique | Sub-technique |
|---|---|---|---|
| Persistence | T1546.015 | Event Triggered Execution | Component Object Model Hijacking |
| Defence Evasion | T1574.001 | Hijack Execution Flow | DLL |
| Collection | T1005 | Data from Local System | - |
| Command and control | T1071.001 | Application Layer Protocol | Web Protocols |
| Command and control | T1105 | Ingress Tool Transfer | - |
| Command and control | T1571 | Non | Standard Port- |
| Command and control | T1573.001 | Encrypted Channel | Symmetric Cryptography |
| Exfiltration | T1041 | Exfiltration Over C2 Channel | - |
| Objective | Behavior ID | Behavior |
|---|---|---|
| Command & Control | B0030 | C2 Communication |
| Impact | B0022 | Remote Access |
| Exfiltration | E1020 | Automated Exfiltration |
| Cryptography Micro-objective | C0027 | Encrypt Data |
| Discovery | E1083 | File and Directory Discovery |
| Anti-Static Analysis | E1027 | Obfuscated Files or Information |
The following reports contain further technical details:
[/emaillocker]