hacker-news · Crawled Jul 20, 2026
HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050
2 IoCs 3 Actors
Read original article ↗
AI Summary
HollowGraph is a newly discovered espionage malware that leverages a compromised Microsoft 365 calendar as a covert command-and-control (C2) channel, hiding operator instructions and exfiltrated data within calendar events dated to 2050. The malware uses legitimate Microsoft Graph API traffic to avoid detection, communicating via encrypted attachments on future-dated events. It is associated with the Cavern backdoor framework and shows potential ties to Iranian-linked actors, though attribution remains unconfirmed. The small, targeted footprint suggests focused cyber espionage rather than broad criminal activity.
AI-extracted · verify before operational use
Extracted Entities 3 found
Indicators of Compromise 2 extracted
MITRE ATT&CK TTPs 17 techniques
T1003 OS Credential Dumping · Credential Access T1027 Obfuscated Files or Information · Defense Evasion T1059 Command and Scripting Interpreter · Execution T1059.001 PowerShell · Execution T1059.007 JavaScript · Execution T1071.001 Web Protocols · Command And Control T1074 Data Staged · Collection T1074.001 Local Data Staging · Collection T1082 System Information Discovery · Discovery T1090 Proxy · Command And Control T1090.003 Multi-hop Proxy · Command And Control T1105 Ingress Tool Transfer · Command And Control T1219 Remote Access Software · Command And Control T1566 Phishing · Initial Access T1573.001 Symmetric Cryptography · Command And Control T1588 Obtain Capabilities · Resource Development T1071.004 DNS · Command And Control