A new malware named HollowGraph has been discovered, which exploits the Microsoft Graph API to transform compromised Microsoft 365 calendars into covert two-way command and control (C2) channels. Researchers from Group-IB identified this malware as part of a targeted operation against Israeli entities, revealing that it is linked to the Cavern backdoor framework. HollowGraph operates through trusted Microsoft services, evading detection by using encrypted communication and DNS tunneling.
Key commands include scheduling appointments with stolen files attached and downloading instructions from planted appointments. Group-IB recommends monitoring Microsoft Graph API activities to identify anomalies.