Researchers have identified HOLLOWGRAPH, a previously undocumented Windows malware implant that uses the Microsoft Graph API and Microsoft 365 calendar events as a covert command-and-control and data exfiltration channel. Group-IB said the malware is a .NET NativeAOT DLL linked with high confidence to the Cavern backdoor framework and observed it in a targeted espionage campaign against Israeli organizations. Investigators saw at least 12 infected systems, with roughly three actively communicating during the analysis window, and said the operation appeared narrowly focused on Israeli-connected victims.
The malware uses a compromised Microsoft 365 mailbox as a two-way dead drop, hiding tasking and stolen data inside calendar events dated 13 May 2050 to reduce the chance of discovery. It supports only the get and send commands and protects Graph API traffic with hybrid RSA-OAEP and AES-256-GCM encryption using separate RSA key pairs for each direction. Researchers also found a secondary DNS tunneling channel over IPv6 AAAA records used to refresh Microsoft Entra ID credentials, with one report tying that activity to the attacker-controlled domain cloudlanecdn[.]com; the refreshed tokens were then stored locally in a file disguised as a log. Group-IB noted some overlap with the Iranian-linked Lyceum cluster, but said that attribution remains unconfirmed and only low confidence.

Get the actors, campaigns, and ATT&CK mapping behind it.
5 events from the most recent confirmed update back to the earliest known activity.
Researchers publicly described HOLLOWGRAPH as a previously undocumented .NET NativeAOT Windows malware implant that abuses Microsoft Graph API calendar events dated 13 May 2050 for covert command-and-control and exfiltration. Group-IB linked the malware with high confidence to the Cavern backdoor framework and noted only low-confidence overlap with Lyceum.
During its investigation, Group-IB identified at least 12 infected systems, with roughly three actively communicating during the analysis window. The activity was assessed as a narrow, targeted espionage campaign against Israeli organizations or Israeli-connected victims.
Group-IB observed HOLLOWGRAPH communicating with attacker infrastructure from early June 2026 as part of a targeted espionage operation affecting Israeli-connected victims. The malware used Microsoft 365 calendar events via the Microsoft Graph API for command-and-control and data exfiltration.
Group-IB reported active HOLLOWGRAPH communications continuing through 9 July 2026. The malware also used DNS tunneling over IPv6 AAAA records to refresh Microsoft Entra ID credentials for continued access to the compromised Microsoft 365 mailbox.
Group-IB reported that HOLLOWGRAPH activity was observed beginning on 3 June 2026 in a targeted espionage campaign affecting Israeli entities or Israeli-connected victims. The malware used compromised Microsoft 365 mailboxes and calendar events via Microsoft Graph API for command-and-control and data exfiltration.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
16 references tracked. Mallory keeps watching after this page renders.
blog.polyswarm.io
Open sourcesecurityweek.com
Open sourcecyberveille.ch
Open sourcecommunity.gurucul.com
Open sourcecyberveille.ch
Open sourcetheregister.com
Open sourceitsecurityguru.org
Open sourcegroup-ib.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.