A recently discovered piece of malware abuses the Microsoft 365 calendar for command-and-control (C&C) communication, Group-IB reports.
Dubbed HollowGraph, the malware is believed to be part of a larger toolkit and is likely linked to Cavern Manticore, an Iran-nexus threat actor that Check Point detailed earlier this month.
The malware’s communication mechanism relies on the Microsoft Graph API and a compromised 365 account in Israel to hide its C&C communication within legitimate traffic.
“Using the Microsoft Graph API, it treats the compromised mailbox’s calendar as a two-way dead-drop: operators plant tasking as calendar events, and the implant exfiltrates stolen files by creating its own events with encrypted data attached,” Group-IB explains.
The payloads are attached to events as files, and the events are dated far in the future (13 May 2050) to avoid alerting the mailbox owner. The malware uses hybrid RSA + AES encryption to secure the payloads.






