HOLLOWGRAPH is a Windows espionage backdoor linked with high confidence to the Cavern command-and-control framework. It is implemented as a .NET NativeAOT-compiled DLL and has been observed masquerading as a legitimate library to reduce suspicion. The malware is designed for stealthy post-compromise operations and uses compromised Microsoft 365 mailboxes as covert infrastructure rather than relying on conventional attacker-hosted command-and-control servers.
Its defining capability is abuse of the Microsoft Graph API to turn a victim’s Microsoft 365 calendar into a bidirectional dead-drop channel. Operators place encrypted tasking in specially crafted calendar events, and the implant retrieves those instructions through Graph API access. For outbound operations, HOLLOWGRAPH encrypts stolen data and exfiltrates it by creating calendar events with attached payloads. Observed tradecraft includes scheduling malicious events far in the future to reduce the likelihood of user discovery. Communications over the Graph channel are protected with hybrid cryptography using RSA-OAEP and AES-256-GCM, with separate key pairs used for inbound and outbound traffic.
HOLLOWGRAPH also maintains a secondary DNS-based channel used to refresh Microsoft Entra ID credentials required for continued Graph API access. Reporting indicates this credential-refresh mechanism uses DNS tunneling over IPv6 AAAA records and writes updated authentication values to local configuration storage. This combination of trusted cloud APIs and DNS-based credential maintenance allows the malware to blend into legitimate enterprise traffic and complicates perimeter-based detection.
Observed functionality supports at least two core commands for retrieving operator instructions and sending exfiltrated data. The malware has been associated with targeted espionage activity focused primarily on Israeli organizations, with multiple infected systems identified during activity observed in mid-2026. Researchers noted technical overlaps with Iranian-nexus operations, including similarities to Lyceum-related tradecraft, but direct attribution to a specific named threat actor remains unconfirmed. The strongest supported linkage is to the broader Cavern framework and its modular espionage ecosystem.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Two back-to-back follow-up reports from Group-IB and Kaspersky detailed another module dubbed HOLLOWGRAPH that turns Microsoft 365 calendars into covert C2 channels.
Researchers at Group-IB dubbed the highly sophisticated malware sample HollowGraph and attributed it, with high confidence, to the Cavern backdoor framework.
Industry researchers identified HOLLOWGRAPH, a newly discovered malware component that it attributes with high confidence to the Cavern backdoor framework. Rather than relying on traditional command-and-control (C2) infrastructure, HOLLOWGRAPH abuses the Microsoft Graph API to transform a compromised Microsoft 365 calendar into a covert communications channel for receiving commands and exfiltrating stolen data.
L’article s’appuie sur l’analyse technique de Group-IB portant sur un implant nommé HollowGraph ... HollowGraph est une petite bibliothèque .NET qui exploite une boîte mail compromise pour établir un canal C2 bidirectionnel via l’API Microsoft Graph.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
The attackers have taken measures to ensure that this file is not suspicious; specifically, it is placed in the known location used by Microsoft Entra ID and has the standard log file name.
The malware uses hybrid RSA + AES encryption to secure the payloads.
HOLLOWGRAPH is a Windows espionage backdoor delivered as a .NET NativeAOT DLL masquerading as a Brotli library.
A newly identified Windows malware sample abuses Microsoft Graph API to transform a compromised Microsoft 365 calendar into a covert two-way command and control (C2) channel. | The malware supports two commands, get and send, and relies entirely on trusted third-party infrastructure for communication, never reaching out directly to attacker-owned servers for payload delivery.
The malware communicates exclusively through Microsoft Graph API requests to a compromised Microsoft 365 mailbox.
The malware, in particular, abuses the Microsoft Graph API to exfiltrate files and receive commands from the attacker using Microsoft 365 calendar events, and DNS tunneling to refresh credentials used in C2 communication.
A newly identified Windows malware sample abuses Microsoft Graph API to transform a compromised Microsoft 365 calendar into a covert two-way command and control (C2) channel.
Using the Microsoft Graph API, it treats the compromised mailbox's calendar as a two-way dead-drop: operators plant tasking as calendar events, and the implant exfiltrates stolen files by creating its own events with encrypted data attached.
Le canal C2 est classifié comme Web Service C2 dans le framework ATT&CK.
Meanwhile, the get command searches for appointments planted by the operator and downloads the attached instructions.
7 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
24 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as another malware example using Microsoft 365/Graph API dead-drop C2.
A .NET NativeAOT-compiled DLL module that abuses the Microsoft Graph API and Microsoft 365 calendar events as a covert two-way dead-drop for command delivery and file exfiltration, with DNS tunneling used to refresh credentials for C2 communication.
A sophisticated backdoor that self-registers in Microsoft Graph API using stolen Microsoft 365 mailbox credentials, hides command-and-control in Microsoft 365 calendar events, exfiltrates stolen data via event attachments, and also uses DNS AAAA records to retrieve updated Microsoft Entra ID credentials for persistence.
A Windows espionage backdoor delivered as a .NET NativeAOT-compiled DLL disguised as a Brotli library. It uses compromised Microsoft 365 calendar events as a command-and-control dead drop for tasking and exfiltration, employs hybrid RSA-OAEP and AES-256-GCM encryption for Graph payloads, and uses DNS tunneling over IPv6 AAAA records to refresh Entra ID credentials and maintain mailbox access after secret rotation.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.