HollowGraph Malware Exploits Microsoft 365 Calendars

Unveiling the HollowGraph Threat
A cloud calendar can conceal far more than mundane appointments; the HollowGraph malware exploits Microsoft 365 to clandestinely receive commands and transmit pilfered files. Cybersecurity experts at Group-IB have detected HollowGraph across a minimum of twelve distinct systems. You can peruse their comprehensive analysis regarding this HollowGraph Microsoft 365 exploitation. The most recent malicious activities transpired during June and July of this year. Accumulated forensic evidence strongly indicates highly targeted attacks against Israeli organizations, presumably orchestrated for sophisticated espionage purposes.
Clandestine Operations and Intricate Mechanics
HollowGraph meticulously targets the Windows operating system. This sophisticated malware breaches compromised Microsoft 365 accounts via the Microsoft Graph interface. The malicious program surreptitiously stores connection credentials, email addresses, and cryptographic keys within a file named logAzure.txt, which is cleverly disguised as a routine system log.
To facilitate command exchange, the malicious operators schedule calendar events for the distant date of May 13, 2050, attaching heavily encrypted files to these entries. HollowGraph systematically scans for these specific event titles, downloads the illicit attachments, and decrypts the hidden instructions. These instructions harbor direct commands to exfiltrate sensitive data from the compromised machine.
This futuristic timestamp merely serves as a clandestine marker. The system executes the commands instantaneously; naturally, the malware does not remain dormant until 2050. During the exfiltration process, HollowGraph encrypts the purloined files, generates a new event on the aforementioned date, and covertly embeds the stolen data as an attachment. Subsequently, the threat actors simply access the compromised calendar and retrieve their ill-gotten contents.
Cryptographic Defenses and Auxiliary Channels
The malware sustains merely two primary commands. The first procures new directives from the calendar, while the second dispatches the accumulated files. HollowGraph elegantly intertwines RSA and AES-256-GCM cryptographic algorithms to independently secure both incoming commands and outgoing transmissions.
An auxiliary communication channel operates via DNS queries. Utilizing these requests, HollowGraph acquires fresh credentials to penetrate Microsoft Entra ID through the cloudlanecdn[.]com domain, subsequently updating the logAzure.txt file and re-establishing its connection to Microsoft Graph.
Attribution and Crucial Mitigation Strategies
With profound confidence, Group-IB correlates HollowGraph to the Cavern framework, previously documented by Check Point specialists. Distinct technical hallmarks closely resemble the sophisticated arsenal of the Iran-linked Lyceum syndicate; however, sufficient empirical data for definitive attribution currently remains elusive.
Security professionals strongly advise organizations to scrutinize their Microsoft Graph and Microsoft 365 logs for chronologically distant events, anomalous titles, and suspicious attachments. Furthermore, implementing rigorous OAuth application oversight, enforcing Conditional Access policies, monitoring outbound DNS requests, and actively hunting for the cloudlanecdn[.]com domain and the logAzure.txt artifact will substantially mitigate potential risks.
Support Our Threat Intelligence
If you find our technology report and cybersecurity news helpful, consider supporting our work.