A new security threat identified as HollowGraph has been reported to misuse the Microsoft 365 calendar for its command-and-control (C&C) operations, according to cybersecurity firm Group-IB.
This malware is thought to be a component of a broader toolkit associated with Cavern Manticore, an Iran-linked threat actor recently analyzed by Check Point. HollowGraph’s unique communication strategy involves the Microsoft Graph API and an infiltrated 365 account based in Israel, enabling it to disguise its C&C activities within legitimate traffic.
Innovative Communication Techniques
HollowGraph cleverly employs the Microsoft Graph API, transforming a compromised mailbox’s calendar into a covert communication channel. Operators insert tasks as calendar events, while the malware fetches stolen data by generating its own events with encrypted attachments, as per Group-IB’s findings.
The malware embeds payloads as files within calendar events, which are postdated to May 13, 2050, to evade detection by the mailbox owner. To secure these payloads, it utilizes a hybrid encryption model combining RSA and AES.
Alternative Communication Channels
Apart from the calendar-based method, HollowGraph also uses DNS tunneling to refresh its settings and obtain Microsoft Entra ID (Azure AD) credentials for authentication. Group-IB has pinpointed 12 victims of HollowGraph, with three actively engaging with the attacker’s infrastructure. The first known interaction took place on June 3, indicating that the malware has been active since at least the previous month.
The indicators recovered, such as an Israeli mailbox used for data theft and malware samples uploaded from Israel, suggest the attackers are specifically targeting Israeli entities rather than conducting a widespread attack.
Technical Characteristics and Attribution
Interestingly, HollowGraph does not connect to an attacker-controlled server for payload distribution. Instead, it relies on two core commands: ‘send’ to create calendar events with file attachments and ‘get’ to locate and retrieve new commands embedded by the operator.
The malware’s hardcoded setup, including the Microsoft Entra ID tenant ID, client ID and secret, target mailbox address, C&C domain, and two RSA keys, is saved on disk as logAzure.txt when executed. Group-IB suggests that HollowGraph is a variant of the Cavern framework and may be linked to the Iran MOIS-connected OilRig subgroup Lyceum (also named Hexane and SiameseKitten), although this attribution is made with low confidence.
Despite the technical parallels with the Iranian-nexus threat actor Lyceum, Group-IB acknowledges that these overlaps are not distinct enough to confirm a high-confidence attribution.
