Description

A newly discovered Windows malware named HOLLOWGRAPH has been identified by Group-IB as a sophisticated threat that abuses the Microsoft Graph API and Microsoft 365 Calendar to create a hidden command-and-control (C2) channel. Instead of using traditional attacker-controlled servers, the malware communicates through encrypted calendar events, allowing threat actors to issue commands and exfiltrate stolen files while blending into legitimate Microsoft 365 traffic. Researchers linked the malware with high confidence to the Cavern backdoor framework, making detection significantly more difficult for security teams. HOLLOWGRAPH is particularly dangerous because it leverages trusted Microsoft cloud services, reducing the likelihood of detection by conventional security tools. The malware stores encrypted commands in calendar event attachments and uploads stolen data by creating new calendar events, while also using DNS tunneling to update Microsoft Entra ID credentials. Since all communications appear as normal Microsoft Graph API traffic, organizations relying solely on network-based monitoring may fail to identify malicious activity. This stealthy approach reflects the growing trend of attackers abusing legitimate cloud platforms to evade defenses. Organizations should strengthen monitoring of Microsoft Graph API activity, enforce multi-factor authentication (MFA) for Microsoft 365 accounts, and regularly review calendar events for suspicious or unexpected entries. Security teams should implement endpoint detection and response (EDR), monitor DNS tunneling behavior, restrict unnecessary API permissions, and maintain up-to-date threat intelligence to detect emerging malware techniques. Regular employee awareness training and prompt investigation of unusual Microsoft 365 activity can further reduce the risk of compromise.