hacker-news · Crawled Jul 20, 2026

HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050

2 IoCs 3 Actors
Read original article ↗

AI Summary

HollowGraph is a newly discovered espionage malware that leverages a compromised Microsoft 365 calendar as a covert command-and-control (C2) channel, hiding operator instructions and exfiltrated data within calendar events dated to 2050. The malware uses legitimate Microsoft Graph API traffic to avoid detection, communicating via encrypted attachments on future-dated events. It is associated with the Cavern backdoor framework and shows potential ties to Iranian-linked actors, though attribution remains unconfirmed. The small, targeted footprint suggests focused cyber espionage rather than broad criminal activity.

AI-extracted · verify before operational use

Extracted Entities 3 found

Indicators of Compromise 2 extracted

Type Value Detail
Domain cloudlanecdn[.]com Details →
Filename logAzure.txt Details →

MITRE ATT&CK TTPs 41 techniques

T1001.002 Steganography · Command And Control T1003 OS Credential Dumping · Credential Access T1003.002 Security Account Manager · Credential Access T1021.001 Remote Desktop Protocol · Lateral Movement T1021.003 Distributed Component Object Model · Lateral Movement T1027 Obfuscated Files or Information · Defense Evasion T1055.001 Dynamic-link Library Injection · Defense Evasion T1059 Command and Scripting Interpreter · Execution T1059.001 PowerShell · Execution T1059.007 JavaScript · Execution T1068 Exploitation for Privilege Escalation · Privilege Escalation T1071.001 Web Protocols · Command And Control T1071.004 DNS · Command And Control T1074 Data Staged · Collection T1074.001 Local Data Staging · Collection T1082 System Information Discovery · Discovery T1085 T1085 T1090 Proxy · Command And Control T1090.003 Multi-hop Proxy · Command And Control T1105 Ingress Tool Transfer · Command And Control T1132.001 Standard Encoding · Command And Control T1204.002 Malicious File · Execution T1219 Remote Access Software · Command And Control T1486 Data Encrypted for Impact · Impact T1543.003 Windows Service · Persistence T1557.001 LLMNR/NBT-NS Poisoning and SMB Relay · Credential Access T1558.003 Kerberoasting · Credential Access T1566 Phishing · Initial Access T1566.002 Spearphishing Link · Initial Access T1573.001 Symmetric Cryptography · Command And Control T1574.002 DLL Side-Loading · Persistence T1588 Obtain Capabilities · Resource Development T1036 Masquerading · Defense Evasion T1036.005 Match Legitimate Name or Location · Defense Evasion T1055 Process Injection · Defense Evasion T1059.003 Windows Command Shell · Execution T1102 Web Service · Command And Control T1114 Email Collection · Collection T1558 Steal or Forge Kerberos Tickets · Credential Access T1566.001 Spearphishing Attachment · Initial Access T1583 Acquire Infrastructure · Resource Development