Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
HollowGraph Malware Exploits Microsoft 365 Calendar for C&C

HollowGraph Malware Exploits Microsoft 365 Calendar for C&C

Posted on July 21, 2026 By CWS

A new security threat identified as HollowGraph has been reported to misuse the Microsoft 365 calendar for its command-and-control (C&C) operations, according to cybersecurity firm Group-IB.

This malware is thought to be a component of a broader toolkit associated with Cavern Manticore, an Iran-linked threat actor recently analyzed by Check Point. HollowGraph’s unique communication strategy involves the Microsoft Graph API and an infiltrated 365 account based in Israel, enabling it to disguise its C&C activities within legitimate traffic.

Innovative Communication Techniques

HollowGraph cleverly employs the Microsoft Graph API, transforming a compromised mailbox’s calendar into a covert communication channel. Operators insert tasks as calendar events, while the malware fetches stolen data by generating its own events with encrypted attachments, as per Group-IB’s findings.

The malware embeds payloads as files within calendar events, which are postdated to May 13, 2050, to evade detection by the mailbox owner. To secure these payloads, it utilizes a hybrid encryption model combining RSA and AES.

Alternative Communication Channels

Apart from the calendar-based method, HollowGraph also uses DNS tunneling to refresh its settings and obtain Microsoft Entra ID (Azure AD) credentials for authentication. Group-IB has pinpointed 12 victims of HollowGraph, with three actively engaging with the attacker’s infrastructure. The first known interaction took place on June 3, indicating that the malware has been active since at least the previous month.

The indicators recovered, such as an Israeli mailbox used for data theft and malware samples uploaded from Israel, suggest the attackers are specifically targeting Israeli entities rather than conducting a widespread attack.

Technical Characteristics and Attribution

Interestingly, HollowGraph does not connect to an attacker-controlled server for payload distribution. Instead, it relies on two core commands: ‘send’ to create calendar events with file attachments and ‘get’ to locate and retrieve new commands embedded by the operator.

The malware’s hardcoded setup, including the Microsoft Entra ID tenant ID, client ID and secret, target mailbox address, C&C domain, and two RSA keys, is saved on disk as logAzure.txt when executed. Group-IB suggests that HollowGraph is a variant of the Cavern framework and may be linked to the Iran MOIS-connected OilRig subgroup Lyceum (also named Hexane and SiameseKitten), although this attribution is made with low confidence.

Despite the technical parallels with the Iranian-nexus threat actor Lyceum, Group-IB acknowledges that these overlaps are not distinct enough to confirm a high-confidence attribution.

Security Week News Tags:C&C communication, Cavern Manticore, Cybersecurity, Group-IB, HollowGraph, Iran-nexus, Lyceum, Malware, Microsoft 365, Microsoft Graph API

Post navigation

Previous Post: SonicWall Flaws Exploited to Deploy Malware
Next Post: Microsoft Defender XDR Vulnerability in Network Detection

Related Posts

TRM Labs Secures M for AI in Blockchain Security TRM Labs Secures $70M for AI in Blockchain Security Security Week News
M WhatsApp Hack Flops: Only Low-Risk Bugs Disclosed to Meta After Pwn2Own Withdrawal $1M WhatsApp Hack Flops: Only Low-Risk Bugs Disclosed to Meta After Pwn2Own Withdrawal Security Week News
RubyGems Halts Registrations Amid Security Threat RubyGems Halts Registrations Amid Security Threat Security Week News
British Department Store Harrods Warns Customers That Some Personal Details Taken in Data Breach British Department Store Harrods Warns Customers That Some Personal Details Taken in Data Breach Security Week News
Siemens, Schneider, and Others Address ICS Vulnerabilities Siemens, Schneider, and Others Address ICS Vulnerabilities Security Week News
Unpatched Tenda Firmware Backdoor Risks Device Security Unpatched Tenda Firmware Backdoor Risks Device Security Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Zimbra Releases Fixes for Critical SNMP and XSS Flaws
  • Iranian APT42 Enhances Phishing Tactics with AI Technology
  • Andreas Gaetje: Journey from Economics to Körber CISO
  • Critical SharePoint Vulnerability CVE-2026-50522 Exploited
  • Craneware Confirms Cyberattack, Data Compromised

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Zimbra Releases Fixes for Critical SNMP and XSS Flaws
  • Iranian APT42 Enhances Phishing Tactics with AI Technology
  • Andreas Gaetje: Journey from Economics to Körber CISO
  • Critical SharePoint Vulnerability CVE-2026-50522 Exploited
  • Craneware Confirms Cyberattack, Data Compromised

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark