New HollowGraph Malware Abuses Microsoft 365 Calendar for C&C Communication
Summary
A new malware strain called HollowGraph has been identified that utilizes a compromised Microsoft 365 account's calendar for command and control (C&C) communication. This technique effectively turns the calendar into a two-way dead-drop for the malware.
IFF Assessment
FOE
This malware's novel use of a legitimate cloud service for C&C communication presents a new challenge for defenders in detecting and blocking malicious activity.
Defender Context
Defenders should be aware of this evolving technique where attackers leverage cloud service features, like calendars, for malicious purposes. Monitoring for unusual calendar activity and ensuring strong authentication for Microsoft 365 accounts are crucial mitigation steps.