HollowGraph Malware Exploits Microsoft 365 Calendar for C&C Activities
A newly identified malicious software employs the Microsoft 365 calendar system to facilitate command-and-control (C&C) operations, according to Group-IB.
Threat Group and Attribution
The malware, named HollowGraph, is part of an extensive toolkit and is suspected to be associated with Cavern Manticore, an Iranian-linked threat group highlighted by Check Point earlier this month.
Technical Details
The malware’s communication method utilizes the Microsoft Graph API and a compromised 365 account based in Israel to conceal C&C traffic within legitimate data flows. The malware uses the compromised email account’s calendar as a bidirectional data exchange mechanism. Attackers embed instructions within calendar entries, which are then retrieved by the malware. Files containing payloads are attached to these entries. Additionally, HollowGraph maintains an auxiliary communication channel that employs DNS tunneling to update its configuration and Microsoft Entra ID (Azure AD) credentials for authentication purposes.
Affected Organizations
Group-IB identified 12 organizations affected by HollowGraph, with three actively engaging with the attackers’ infrastructure. The earliest recorded activity dates back to June 3, indicating the malware has been deployed in attacks for at least a month.
Indicators of Compromise
The indicators of compromise, including an Israeli mailbox used for data exfiltration and malware samples originating from Israel, suggest a targeted approach toward Israeli entities rather than widespread, opportunistic breaches.
Command and Control Mechanisms
HollowGraph does not directly connect to an attacker-controlled server for payload delivery. Instead, it utilizes two primary commands: “send” to create calendar appointments with attached files and “get” to retrieve appointments planted by the threat actors. Upon execution, the malware writes its hardcoded configuration—containing the Microsoft Entra ID tenant ID, client ID, secret, target mailbox address, C&C domain, and two RSA keys—into a file named logAzure.txt.
Attribution and Analysis
Group-IB’s analysis suggests HollowGraph may be a variant of the Cavern framework but attributes it to the Iran MOIS-linked OilRig subgroup Lyceum (also known as Hexane and SiameseKitten) with limited confidence. The report notes technical similarities with Lyceum but emphasizes these overlaps are not distinctive enough to confirm a high-confidence attribution.
Security Recommendations
The malware’s operational methods highlight evolving tactics by threat actors to leverage legitimate cloud services for covert communication. The use of calendar-based dead drops and DNS tunneling underscores the challenges in detecting such advanced persistent threats. Security researchers advise organizations to monitor for anomalous calendar activity and implement strict access controls for Microsoft 365 environments.
