HOLLOWGRAPH is a Windows malware implant used in targeted espionage operations that abuses compromised Microsoft 365 mailboxes as covert command-and-control infrastructure. Implemented as a .NET NativeAOT DLL and linked with high confidence to the Cavern backdoor framework, it uses the Microsoft Graph API to blend malicious traffic into legitimate Microsoft 365 activity rather than relying on conventional attacker-controlled servers. Observed activity indicates a narrow operational focus on Israeli organizations, while any linkage to Lyceum or other Iranian-nexus actors remains low-confidence and unconfirmed.
The implant turns a compromised mailbox calendar into a two-way dead drop. Operators place encrypted tasking in calendar events, and the malware retrieves and decrypts those instructions through Graph API access. For exfiltration, it creates its own far-future calendar events and uploads encrypted stolen data as attachments, using dates intended to reduce the likelihood of user discovery. HOLLOWGRAPH is consistently described as supporting two core commands, get and send, corresponding to task retrieval and data exfiltration.
HOLLOWGRAPH protects its Graph-based communications with hybrid cryptography using RSA and AES-256-GCM, with separate key material for inbound tasking and outbound exfiltration. It also maintains a secondary DNS tunneling channel used to refresh Microsoft Entra ID application credentials required for continued Graph API access. Updated configuration values are stored locally in a disguised log file. This combination of trusted cloud services, covert mailbox abuse, encrypted payload handling, and auxiliary DNS-based credential refresh makes HOLLOWGRAPH a stealth-oriented post-compromise espionage component designed for persistent operator access and discreet data theft.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
A stealthy new malware strain called HOLLOWGRAPH that hijacks Microsoft 365 calendars to secretly communicate with hackers, disguising malicious commands as ordinary calendar invites.
A stealthy new malware strain called HOLLOWGRAPH that hijacks Microsoft 365 calendars to secretly communicate with hackers, disguising malicious commands as ordinary calendar invites.
A stealthy new malware strain called HOLLOWGRAPH that hijacks Microsoft 365 calendars to secretly communicate with hackers, disguising malicious commands as ordinary calendar invites.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
To remain under the radar, the threat actor creates calendar events dated May 13, 2050, with the title in specific formats. Commands and exfiltrated data are concealed within files attached to these calendar entries.
disguising malicious commands as ordinary calendar invites ... storing the updated values in a file disguised as an innocent log file, logAzure.txt.
The malware uses hardcoded credentials to authenticate to the Microsoft Graph API via a compromised Microsoft 365 account.
La configuration est stockée sur disque dans le fichier logAzure.txt
The malware uses hardcoded credentials to authenticate to the Microsoft Graph API via a compromised Microsoft 365 account. | A new malware component called HollowGraph has been identified ... that leverages the calendar feature within compromised Microsoft 365 mailboxes to act as a command-and-control channel.
the approach moves tasking and stolen data through legitimate Microsoft Graph API traffic, so the activity looks like ordinary Microsoft 365 chatter
An additional channel via DNS tunneling is used to update Microsoft Entra ID details.
HollowGraph has been identified ... that leverages the calendar feature within compromised Microsoft 365 mailboxes to act as a command-and-control channel.
Il exploite l’API Microsoft Graph via une boîte mail Microsoft 365 compromise (domaine .co.il) pour établir un canal C2 dissimulé dans le trafic légitime Microsoft.
The get path retrieves encrypted instructions from calendar event attachments.
Commande send : chiffre les fichiers volés... Chiffrement hybride RSA-OAEP + AES-256-GCM
Commands and exfiltrated data are hidden within files attached to calendar events scheduled for May 13, 2050. HollowGraph supports GET and SEND commands to retrieve instructions and send stolen data, respectively.
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malware component used for espionage that abuses compromised Microsoft 365 mailboxes and the Microsoft Graph API for command-and-control. It hides commands and exfiltrated data in calendar event attachments, supports GET and SEND tasking, uses RSA plus AES-256-GCM for protected communications, and can use DNS tunneling to update Microsoft Entra ID details.
A .NET-compiled malware component that abuses the Microsoft Graph API through a compromised Microsoft 365 account, using the victim mailbox calendar as a covert two-way dead drop for command-and-control and exfiltration. It supports 'get' and 'send' commands, hides exfiltrated data in encrypted calendar event attachments, schedules malicious events far in the future to avoid user notice, and uses DNS tunneling via IPv6 AAAA queries to refresh Microsoft Entra ID credentials.
A Windows malware component/backdoor that uses a compromised Microsoft 365 mailbox calendar and Microsoft Graph API as a covert command-and-control channel. Operators place commands in calendar events and exfiltrate encrypted stolen files as event attachments; it also uses a secondary DNS tunneling channel.
A newly discovered espionage implant/backdoor implemented as a .NET DLL that uses a hijacked Microsoft 365 calendar via Microsoft Graph API as a dead-drop command-and-control and exfiltration channel. It retrieves operator tasking from far-future calendar events and exfiltrates encrypted stolen files as event attachments. It also uses DNS AAAA records to refresh Entra ID application credentials and target mailbox configuration.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.