Threat Advisory

HOLLOWGRAPH Malware Uses Microsoft Graph API as Covert Two-Way Command-and-Control Channel

Threat: Malware
Targeted Region: Israel
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

HOLLOWGRAPH is a newly identified Windows espionage malware that transforms a compromised Microsoft 365 environment into a covert command-and-control (C2) platform. Rather than relying on attacker-controlled servers, the malware abuses the Microsoft Graph API to communicate through a victim's Microsoft 365 calendar, allowing malicious traffic to blend seamlessly with legitimate cloud activity. Attackers issue commands by creating calendar events, while the malware exfiltrates stolen files by uploading encrypted attachments to newly created events. To avoid detection by users, all malicious calendar entries are scheduled far into the future, specifically in the year 2050. HOLLOWGRAPH also maintains persistence by refreshing its Microsoft Entra ID (Azure AD) credentials through DNS tunneling, enabling continued access even if credentials change. The malware has been linked with high confidence to the Cavern backdoor framework based on shared command structures and operational characteristics, although attribution to a specific threat actor remains inconclusive. Researchers identified at least 12 compromised systems, with evidence indicating a highly targeted cyber espionage campaign primarily focused on Israeli organizations rather than indiscriminate, large-scale attacks.

HOLLOWGRAPH is implemented as a .NET NativeAOT-compiled DLL and is designed around a minimal yet effective command set consisting of only get and send operations. The malware uses the Microsoft Graph API as its primary communication channel, treating a compromised Microsoft 365 calendar as a dead-drop repository where attackers hide encrypted instructions inside calendar events and retrieve exfiltrated data from event attachments. Every malicious event is timestamped for May 2050, reducing the likelihood of user discovery. To protect communications, HOLLOWGRAPH employs hybrid cryptography, combining RSA-OAEP and AES-256-GCM with separate key pairs for inbound tasking and outbound data exfiltration. A secondary DNS tunneling channel periodically retrieves updated Microsoft Entra ID credentials by encoding configuration data within IPv6 AAAA DNS responses from an attacker-controlled domain. The malware stores configuration details, including tenant identifiers, application credentials, mailbox information, and cryptographic keys, in a local file named logAzure.txt. Analysis also revealed command syntax and communication patterns closely matching the Cavern framework, indicating that HOLLOWGRAPH is likely part of a larger modular cyber espionage toolkit.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

HOLLOWGRAPH is a newly identified Windows espionage malware that transforms a compromised Microsoft 365 environment into a covert command-and-control (C2) platform. Rather than relying on attacker-controlled servers, the malware abuses the Microsoft Graph API to communicate through a victim's Microsoft 365 calendar, allowing malicious traffic to blend seamlessly with legitimate cloud activity. Attackers issue commands by creating calendar events, while the malware exfiltrates stolen files by uploading encrypted attachments to newly created events. To avoid detection by users, all malicious calendar entries are scheduled far into the future, specifically in the year 2050. HOLLOWGRAPH also maintains persistence by refreshing its Microsoft Entra ID (Azure AD) credentials through DNS tunneling, enabling continued access even if credentials change. The malware has been linked with high confidence to the Cavern backdoor framework based on shared command structures and operational characteristics, although attribution to a specific threat actor remains inconclusive. Researchers identified at least 12 compromised systems, with evidence indicating a highly targeted cyber espionage campaign primarily focused on Israeli organizations rather than indiscriminate, large-scale attacks.

HOLLOWGRAPH is implemented as a .NET NativeAOT-compiled DLL and is designed around a minimal yet effective command set consisting of only get and send operations. The malware uses the Microsoft Graph API as its primary communication channel, treating a compromised Microsoft 365 calendar as a dead-drop repository where attackers hide encrypted instructions inside calendar events and retrieve exfiltrated data from event attachments. Every malicious event is timestamped for May 2050, reducing the likelihood of user discovery. To protect communications, HOLLOWGRAPH employs hybrid cryptography, combining RSA-OAEP and AES-256-GCM with separate key pairs for inbound tasking and outbound data exfiltration. A secondary DNS tunneling channel periodically retrieves updated Microsoft Entra ID credentials by encoding configuration data within IPv6 AAAA DNS responses from an attacker-controlled domain. The malware stores configuration details, including tenant identifiers, application credentials, mailbox information, and cryptographic keys, in a local file named logAzure.txt. Analysis also revealed command syntax and communication patterns closely matching the Cavern framework, indicating that HOLLOWGRAPH is likely part of a larger modular cyber espionage toolkit.[emaillocker id="1283"]

HOLLOWGRAPH demonstrates the growing sophistication of modern cyber espionage operations by exploiting trusted cloud services instead of traditional attacker-controlled infrastructure. By leveraging Microsoft Graph API and legitimate Microsoft 365 calendar functionality, the malware effectively disguises malicious communications as normal enterprise cloud traffic, significantly reducing the effectiveness of conventional network-based detection mechanisms. Its additional use of DNS tunneling for credential renewal, strong hybrid encryption, and narrowly focused victim selection reflects a mature and well-resourced adversary with advanced operational security practices. Although the malware has been associated with the Cavern framework and shows similarities to activity previously linked to Iranian-aligned operations, current evidence is insufficient for definitive attribution to any known threat actor. The campaign appears highly selective, targeting a limited number of Israeli entities rather than conducting broad opportunistic attacks, indicating an intelligence-gathering objective. The discovery highlights the increasing abuse of trusted SaaS platforms as covert communication channels and emphasizes the need for organizations to monitor Microsoft Graph API activity, abnormal calendar operations, cloud identity usage, and DNS anomalies to detect advanced threats that intentionally blend into legitimate enterprise environments.

THREAT PROFILE:

Tactic Technique Id Technique Sub-technique
Persistence T1546.015 Event Triggered Execution Component Object Model Hijacking
Defence Evasion T1574.001 Hijack Execution Flow DLL
Collection T1005 Data from Local System -
Command and control T1071.001 Application Layer Protocol Web Protocols
Command and control T1105 Ingress Tool Transfer -
Command and control T1571 Non Standard Port-
Command and control T1573.001 Encrypted Channel Symmetric Cryptography
Exfiltration T1041 Exfiltration Over C2 Channel -

MBC MAPPING:

Objective Behavior ID Behavior
Command & Control B0030 C2 Communication
Impact B0022 Remote Access
Exfiltration E1020 Automated Exfiltration
Cryptography Micro-objective C0027 Encrypt Data
Discovery E1083 File and Directory Discovery
Anti-Static Analysis E1027 Obfuscated Files or Information

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu