New HollowGraph malware uses Microsoft Graph for stealthy C2 comms

A New Wave of Stealthy Malware Exploits Microsoft 365 to Exfiltrate Data

In a concerning development, researchers have discovered a sophisticated malware module called HollowGraph that uses the calendar feature in compromised Microsoft 365 mailboxes as a command-and-control channel for stealthy communication. The malicious component, which is part of the Cavern framework linked to an Iranian threat actor targeting entities in Israel, has been found on at least 12 systems.

HollowGraph works by using hardcoded details to authenticate with the Microsoft Graph API via a compromised Microsoft 365 account. This allows it to create calendar events dated May 13, 2050, which serve as covert dead-drops for commands and exfiltrated data. The malware uses a hybrid encryption scheme that mixes RSA and AES-256-GCM algorithms to secure communication over Microsoft Graph, keeping inbound and outbound channels cryptographically separated.

The threat actor behind HollowGraph appears to be focused on organizations in Israel, suggesting a targeted attack for espionage purposes. Researchers have identified several technical similarities between HollowGraph and the Iranian-nexus threat actor Lyceum, although the available evidence is insufficient to attribute the activity with high confidence.

To remain under the radar, HollowGraph uses a DNS tunnelling mechanism to receive new Microsoft Entra ID details, which are then used to authenticate to Microsoft Graph. The malware assembles the payload from IPv6 AAAA record queries to the attacker-controlled domain cloudlanecdn[.]com and decodes it as UTF-8 text.

Group-IB’s analysis suggests that HollowGraph demonstrates a high level of technical sophistication, with the threat actor possessing significant technical capabilities and operational maturity. To mitigate the risk, organizations are advised to monitor Microsoft Graph and Microsoft 365 audit logs for suspicious application-driven calendar activity, particularly events in the far future, and unusual subjects and attachments.

In addition, security teams should look out for indicators such as the ‘cloudlanecdn[.]com’ domain and the ‘logAzure.txt’ file. Enforcing Conditional Access, restricting and auditing OAuth client-credential applications, and monitoring outbound DNS for tunneling patterns are also recommended. The discovery of HollowGraph serves as a reminder that even trusted cloud infrastructure can be exploited by sophisticated threat actors.

As the cyber threat landscape continues to evolve, it is essential for organizations to stay vigilant and implement robust security measures. By testing every layer before attackers do, security teams can better detect and prevent such stealthy attacks from succeeding.


Source: Bleeping Computer — 2026-07-20