New HollowGraph malware uses Microsoft Graph for stealthy C2 comms
HollowGraph leverages Microsoft 365 calendar events via Graph API as a covert C2 channel, exploiting trusted cloud infrastructure to evade network-level detection — a pattern European enterprises relying heavily on M365 should treat as an urgent detection gap.
Summary written by editorial AI · Source link below
A malicious component dubbed HollowGraph uses the calendar feature in compromised Microsoft 365 mailboxes as a command-and-control channel to receive attacker commands and exfiltrate stolen data. [...]
Editorial Analysis
Framed for the SOC Analyst desk
HollowGraph's use of Microsoft Graph calendar events as a C2 channel requires new detection rules targeting unusual Graph API patterns and mailbox calendar anomalies.
Develop detection analytics for abnormal Microsoft Graph calendar read/write operations and correlate with endpoint telemetry for known HollowGraph IOCs.
Attackers are hiding command-and-control traffic inside Microsoft 365 calendar entries, requiring updated cloud monitoring to detect.
Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.
External link — opens at BleepingComputer in a new tab.
More from the Threat Intel Desk
- Attackers Combo Up Evasion Tactics for BEC Phishing20 Jul
- Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign20 Jul
- Hackers were inside South Korea's diplomat training system for 9 months20 Jul
- Romania races to restore land registry after cyberattack disrupts property market20 Jul
- HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 205020 Jul