Microsoft 365 calendars become spy drop boxes in HOLLOWGRAPH campaign

Summary

A new malware campaign dubbed HOLLOWGRAPH is exploiting Microsoft 365 calendars to store malicious commands. Attackers create calendar appointments far in the future (e.g., year 2050) with hidden commands in the description, which then get executed.

IFF Assessment

FOE

This campaign leverages legitimate cloud services to evade detection, making it a sophisticated threat for defenders.

Defender Context

Defenders should be aware of this novel technique that weaponizes cloud-based scheduling tools. Monitoring for unusually distant calendar appointments with suspicious content and ensuring robust endpoint detection and response (EDR) solutions are in place to catch any executed commands are crucial mitigation strategies.

Read Full Story →