New HollowGraph malware uses Microsoft Graph for stealthy C2 comms
A malicious component dubbed HollowGraph uses the calendar feature in compromised Microsoft 365 mailboxes as a command-and-control channel to receive attacker commands and exfiltrate stolen data. Researchers analysing the module believe it is part of the Cavern command-an…
Intelligence analysis by Llama

HollowGraph uses the calendar feature in compromised Microsoft 365 mailboxes as a command-and-control channel to receive attacker commands and exfiltrate stolen data. It is part of the Cavern command-and-control framework linked to an Iranian threat actor targeting entities in Israel.
Imagine a hacker using a calendar in a Microsoft 365 mailbox to send secret messages to their friends. But instead of sending messages, they're sending instructions to steal data from the company. This is what HollowGraph does, and it's a very sneaky way for hackers to get what they want.
Analysis
A Malicious Component in the Cloud
HollowGraph is a malicious component that uses the calendar feature in compromised Microsoft 365 mailboxes as a command-and-control channel to receive attacker commands and exfiltrate stolen data. This module is part of the Cavern command-and-control framework, which has been previously linked to an Iranian threat actor targeting entities in Israel.
Technical Sophistication
HollowGraph demonstrates a high level of technical sophistication. Its use of trusted cloud infrastructure for command-and-control, hybrid encryption, DNS tunneling for credential refresh, and highly selective victim targeting collectively suggest that the threat actor possesses significant technical capabilities and operational maturity.
Indicators of Compromise
Organizations should monitor Microsoft Graph and Microsoft 365 audit logs for suspicious application-driven calendar activity, particularly events in the far future, and unusual subjects and attachments. They should also look for indicators such as the ‘cloudlanecdn[.]com’ domain and the ‘logAzure.txt’ file, enforce Conditional Access, restrict and audit OAuth client-credential applications, and monitor outbound DNS for tunneling patterns.
Key points
- HollowGraph uses the calendar feature in compromised Microsoft 365 mailboxes as a command-and-control channel to receive attacker commands and exfiltrate stolen data.
- It is part of the Cavern command-and-control framework linked to an Iranian threat actor targeting entities in Israel.
- HollowGraph demonstrates a high level of technical sophistication and uses trusted cloud infrastructure for command-and-control, hybrid encryption, DNS tunneling for credential refresh, and highly selective victim targeting.
- Organizations should monitor Microsoft Graph and Microsoft 365 audit logs for suspicious application-driven calendar activity and look for indicators such as the ‘cloudlanecdn[.]com’ domain and the ‘logAzure.txt’ file.
If this development plays out positively, organizations may be able to better detect and prevent similar attacks by monitoring Microsoft Graph and Microsoft 365 audit logs for suspicious activity. This could lead to improved security measures and a reduction in the number of successful attacks.
If this development plays out negatively, organizations may be more vulnerable to attacks like HollowGraph, which could lead to significant data breaches and financial losses. This could also embolden threat actors to use similar tactics, making it harder for organizations to detect and prevent attacks.



