New HollowGraph malware uses Microsoft Graph for stealthy C2 comms
HollowGraph leverages Microsoft 365 calendar events via Graph API as a covert C2 channel, exploiting trusted cloud infrastructure to evade network-level detection — a pattern European enterprises relying heavily on M365 should treat as an urgent detection gap.
Summary written by editorial AI · Source link below
A malicious component dubbed HollowGraph uses the calendar feature in compromised Microsoft 365 mailboxes as a command-and-control channel to receive attacker commands and exfiltrate stolen data. [...]
Editorial Analysis
Framed for the CISO & Security Leaders desk
Abusing trusted Microsoft 365 infrastructure for C2 makes detection significantly harder and could bypass traditional perimeter controls across enterprise tenants.
Assess your Microsoft 365 tenant logs for anomalous calendar API activity and review conditional access policies for Graph API usage.
Attackers are hiding command-and-control traffic inside Microsoft 365 calendar entries, requiring updated cloud monitoring to detect.
Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.
External link — opens at BleepingComputer in a new tab.
More from the Threat Intel Desk
- Attackers Combo Up Evasion Tactics for BEC Phishing20 Jul
- Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign20 Jul
- Hackers were inside South Korea's diplomat training system for 9 months20 Jul
- Romania races to restore land registry after cyberattack disrupts property market20 Jul
- HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 205020 Jul