HOLLOWGRAPH is a Windows espionage backdoor associated with the Cavern framework and used in a targeted campaign focused on Israeli entities. Implemented as a .NET NativeAOT DLL, it abuses a compromised Microsoft 365 mailbox and the Microsoft Graph API to turn the victim’s calendar into a covert two-way dead-drop channel for command-and-control and data exfiltration. Operators place encrypted tasking in specially crafted calendar events, and the implant exfiltrates stolen data by creating its own encrypted calendar appointments with attachments, allowing malicious traffic to blend into legitimate Microsoft 365 activity rather than relying on conventional attacker-controlled infrastructure.
The malware supports at least two core commands, commonly described as get and send. Its Graph-based communications are protected with hybrid cryptography using RSA and AES-256-GCM, with separate key pairs for inbound and outbound traffic. HOLLOWGRAPH also uses a secondary DNS tunneling channel over IPv6 AAAA queries to refresh Microsoft Entra ID credentials needed to maintain access to the cloud channel. Configuration data, including authentication material and communication parameters, is stored locally in a file disguised as a log. Researchers linked HOLLOWGRAPH with high confidence to the Cavern backdoor framework based on matching command syntax and task formatting, while noting only low-confidence technical overlap with the Iranian-nexus actor Lyceum. The activity is assessed as deliberate cyber espionage rather than opportunistic crime.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Researchers at Group-IB dubbed the highly sophisticated malware sample HollowGraph and attributed it, with high confidence, to the Cavern backdoor framework.
The disclosure comes days after Group-IB uncovered a new malware sample codenamed HOLLOWGRAPH... "HOLLOWGRAPH abuses Microsoft Graph API to transform a compromised Microsoft 365 calendar into a covert two-way command-and-control channel."
Industry researchers identified HOLLOWGRAPH, a newly discovered malware component that it attributes with high confidence to the Cavern backdoor framework. Rather than relying on traditional command-and-control (C2) infrastructure, HOLLOWGRAPH abuses the Microsoft Graph API to transform a compromised Microsoft 365 calendar into a covert communications channel for receiving commands and exfiltrating stolen data.
L’article s’appuie sur l’analyse technique de Group-IB portant sur un implant nommé HollowGraph ... HollowGraph est une petite bibliothèque .NET qui exploite une boîte mail compromise pour établir un canal C2 bidirectionnel via l’API Microsoft Graph.
22 distinct techniques documented for this family, organized by ATT&CK tactic.
The attackers have taken measures to ensure that this file is not suspicious; specifically, it is placed in the known location used by Microsoft Entra ID and has the standard log file name.
The malware uses hybrid RSA + AES encryption to secure the payloads.
HOLLOWGRAPH is a Windows espionage backdoor delivered as a .NET NativeAOT DLL masquerading as a Brotli library.
The HollowGraph malware component is designed to self-register in the Microsoft Graph API using the credentials stolen from the Microsoft 365 mailbox.
A newly identified Windows malware sample abuses Microsoft Graph API to transform a compromised Microsoft 365 calendar into a covert two-way command and control (C2) channel. | The malware supports two commands, get and send, and relies entirely on trusted third-party infrastructure for communication, never reaching out directly to attacker-owned servers for payload delivery.
The malware communicates exclusively through Microsoft Graph API requests to a compromised Microsoft 365 mailbox.
HollowGraph also uses DNS tunneling to deliver and refresh Microsoft Entra ID (Azure AD) credentials needed to authenticate to the Graph channel.
A newly identified Windows malware sample abuses Microsoft Graph API to transform a compromised Microsoft 365 calendar into a covert two-way command and control (C2) channel.
Researchers note that the mailbox calendars are used as a “dead drop” to store the data; hence, HollowGraph does not use traditional C2 servers to avoid detection.
Le canal C2 est classifié comme Web Service C2 dans le framework ATT&CK.
Meanwhile, the get command searches for appointments planted by the operator and downloads the attached instructions.
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
22 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A sophisticated backdoor that self-registers in Microsoft Graph API using stolen Microsoft 365 mailbox credentials, hides command-and-control in Microsoft 365 calendar events, exfiltrates stolen data via event attachments, and also uses DNS AAAA records to retrieve updated Microsoft Entra ID credentials for persistence.
A Windows espionage backdoor delivered as a .NET NativeAOT-compiled DLL disguised as a Brotli library. It uses compromised Microsoft 365 calendar events as a command-and-control dead drop for tasking and exfiltration, employs hybrid RSA-OAEP and AES-256-GCM encryption for Graph payloads, and uses DNS tunneling over IPv6 AAAA records to refresh Entra ID credentials and maintain mailbox access after secret rotation.
A malware sample linked to the Cavern framework that uses Microsoft Graph API and a compromised Microsoft 365 calendar as a covert two-way C2 dead-drop channel for tasking and exfiltration.
Malware mentioned only in a separate headline on the page, not part of the main incident described.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.