bleeping-computer · Crawled Jul 20, 2026
New HollowGraph malware uses Microsoft Graph for stealthy C2 comms
2 IoCs 1 Actors
Read original article ↗
AI Summary
A newly identified malware named HollowGraph leverages compromised Microsoft 365 accounts and the Microsoft Graph API for command-and-control (C2) communications, using calendar events as a covert channel to send and receive encrypted commands and exfiltrated data. The malware is associated with the Cavern C2 framework and shows technical similarities to the Iranian-linked threat actor Lyceum, though attribution remains unconfirmed. HollowGraph employs hybrid encryption (RSA and AES-256-GCM), DNS tunneling for credential updates, and targets organizations in Israel for espionage purposes.
AI-extracted · verify before operational use
Extracted Entities 1 found
Indicators of Compromise 2 extracted
MITRE ATT&CK TTPs 13 techniques
T1003 OS Credential Dumping · Credential Access T1027 Obfuscated Files or Information · Defense Evasion T1059 Command and Scripting Interpreter · Execution T1059.001 PowerShell · Execution T1071.001 Web Protocols · Command And Control T1071.004 DNS · Command And Control T1074 Data Staged · Collection T1074.001 Local Data Staging · Collection T1082 System Information Discovery · Discovery T1090 Proxy · Command And Control T1105 Ingress Tool Transfer · Command And Control T1566 Phishing · Initial Access T1588 Obtain Capabilities · Resource Development