A newly identified malware called HollowGraph utilizes the Microsoft 365 calendar for command-and-control communication, as reported by Group-IB. This malware, linked to the Iran-nexus threat actor Cavern Manticore, obscures its activities by hiding within legitimate traffic via the Microsoft Graph API.
The malware uses a compromised 365 account in Israel and employs a unique method of data exfiltration and tasking through calendar events, which are triggered by the malware creating future-dated events to avoid detection. HollowGraph has affected specific Israeli targets and operates through a low-confidence attribution to the Iran-linked Lyceum subgroup. The malware features hybrid encryption and retains a secondary DNS tunneling channel for updated configurations.