THE HOLLOWGRAPH malware, linked to the Cavern backdoor framework, exploits the Microsoft Graph API to hide its command-and-control (C2) operations within Microsoft 365 calendar events, specifically dated far into the future (2050). The malware operates via a compromised Microsoft 365 account targeting Israeli entities, allowing for two-way communication disguised as ordinary calendar activity. It supports commands to retrieve and send information, utilizing encryption to secure its operations.
Group-IB's analysis identifies at least 12 infected systems, noting a low-confidence connection to the Iranian Lyceum group. Detection strategies suggest focusing on unusual Graph API activity and monitoring for future-dated calendar entries.