HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050

Summary

A new espionage malware named HollowGraph has been discovered that utilizes Microsoft 365 calendars as a command and control channel. It hides operator instructions and exfiltrates stolen files as attachments within calendar events dated far in the future, specifically 2050.

IFF Assessment

FOE

This malware's novel approach of using legitimate Microsoft 365 calendar events for command and control and data exfiltration poses a new challenge for defenders, making it harder to detect malicious activity.

Defender Context

Defenders need to be aware of sophisticated techniques that blend malicious activity with legitimate cloud service traffic. Monitoring unusual calendar event activity, especially with future dates, and scrutinizing Microsoft Graph API usage could help identify such threats.

Read Full Story →