New HollowGraph malware uses Microsoft Graph for stealthy C2 comms
Summary
A new malware component named HollowGraph has been identified, utilizing the calendar feature within compromised Microsoft 365 mailboxes to establish a stealthy command-and-control (C2) channel. This allows attackers to receive instructions and exfiltrate sensitive data without raising immediate suspicion.
IFF Assessment
The discovery of new malware that leverages legitimate cloud services for C2 communication poses a significant threat to defenders by making detection and mitigation more challenging.
Defender Context
Defenders need to be aware of sophisticated malware like HollowGraph that abuses cloud service features for C2. Monitoring for unusual calendar activity and suspicious data exfiltration patterns within Microsoft 365 environments is crucial. This trend highlights the growing need for advanced threat detection that can distinguish malicious use of cloud functionalities from legitimate operations.