Malware

HollowGraph Malware Exploits Microsoft Graph

July 20, 2026 20:03 · 12 min read
HollowGraph Malware Exploits Microsoft Graph

HollowGraph Malware: A Stealthy Threat

Researchers have discovered a new malicious component, dubbed HollowGraph, which utilizes the calendar feature in compromised Microsoft 365 mailboxes as a command-and-control channel. This allows attackers to receive commands and exfiltrate stolen data, all while remaining under the radar.

Microsoft 365 Mailbox Abuse

According to a report by cybersecurity company Group-IB, HollowGraph uses hardcoded details to authenticate to the Microsoft Graph API via a compromised Microsoft 365 account. The configuration file, stored as logAzure.txt, includes the Microsoft Entra ID tenant ID, application (client) ID, client secret, target mailbox address, command-and-control (C2) domain, and two RSA keys.

These cryptographic keys are used to encrypt files before delivery to the attacker and to decrypt incoming tasks. To avoid detection, the threat actor creates calendar events dated May 13, 2050, with the title in specific formats. Commands and exfiltrated data are concealed within files attached to these calendar entries.

Commands and Communication

HollowGraph supports two commands: GET and SEND. The GET command allows the malware to search for entries in the format 'Event ID: <7-char-taskID>', download and decrypt received instructions. The SEND command enables the creation of a calendar entry in the format 'Boss{..}ID{..}' and attaches stolen data encrypted with the public RSA key.

Researchers describe the mailbox calendar as a “covert dead-drop,” with HollowGraph retrieving commands from events scheduled within a fixed one-hour window between 22:00 and 23:00 UTC on May 13, 2050. Group-IB explains that the threat actor uses a hybrid encryption scheme that mixes RSA and AES-256-GCM algorithms to secure communication over Microsoft Graph.

Operational Overview

HollowGraph has a second, unencrypted communication channel through DNS tunneling, which is used to receive new Microsoft Entra ID details to authenticate to Microsoft Graph. It retrieves the values through IPv6 AAAA record queries to the attacker-controlled domain cloudlanecdn[.]com and updates the configuration files stored as logAzure.txt.

“Each returned IPv6 address (16 bytes) yields 14 usable payload bytes,” Group-IB explains. The malware assembles the payload from these 14-byte chunks, decodes it as UTF-8 text, and stores the result according to the corresponding configuration field.

“HOLLOWGRAPH demonstrates a high level of technical sophistication. Its use of trusted cloud infrastructure for command-and-control, hybrid encryption, DNS tunneling for credential refresh, and highly selective victim targeting collectively suggest that the threat actor possesses significant technical capabilities and operational maturity,” - Group-IB

Attribution and Recommendations

While researchers cannot attribute HollowGraph to a known threat actor with high confidence, their analysis identified several technical similarities with the Iranian-nexus threat actor Lyceum. However, the available evidence is insufficient to attribute the activity to the threat actor with high confidence.

Group-IB suggests that organizations monitor Microsoft Graph and Microsoft 365 audit logs for suspicious application-driven calendar activity, particularly events in the far future, and unusual subjects and attachments. It is also recommended to look for indicators such as the ‘cloudlanecdn[.]com’ domain and the ‘logAzure.txt’ file, enforce Conditional Access, restrict and audit OAuth client-credential applications, and monitor outbound DNS for tunneling patterns.

Security teams should test every layer before attackers do, as 54% of successful attacks are logged by security teams, while only 14% of alerts are raised. The rest move through the environment unseen, highlighting the need for robust security measures.


Source: BleepingComputer

Source: BleepingComputer

Powered by ZeroBot

Protect your website from bots, scrapers, and automated threats.

Try ZeroBot Free