hacker-news · Crawled Jul 20, 2026

HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050

2 IoCs 3 Actors
Read original article ↗

AI Summary

HollowGraph is a newly discovered espionage malware that leverages a compromised Microsoft 365 calendar as a covert command-and-control (C2) channel, hiding operator instructions and exfiltrated data within calendar events dated to 2050. The malware uses legitimate Microsoft Graph API traffic to avoid detection, communicating via encrypted attachments on future-dated events. It is associated with the Cavern backdoor framework and shows potential ties to Iranian-linked actors, though attribution remains unconfirmed. The small, targeted footprint suggests focused cyber espionage rather than broad criminal activity.

AI-extracted · verify before operational use

Extracted Entities 3 found

Indicators of Compromise 2 extracted

Type Value Detail
Domain cloudlanecdn[.]com Details →
Filename logAzure.txt Details →

MITRE ATT&CK TTPs 17 techniques