New HollowGraph malware uses Microsoft Graph for stealthy C2 comms
HollowGraph leverages Microsoft 365 calendar events via Graph API as a covert C2 channel, exploiting trusted cloud infrastructure to evade network-level detection — a pattern European enterprises relying heavily on M365 should treat as an urgent detection gap.
Summary written by editorial AI · Source link below
A malicious component dubbed HollowGraph uses the calendar feature in compromised Microsoft 365 mailboxes as a command-and-control channel to receive attacker commands and exfiltrate stolen data. [...]
Editorial Analysis
Enterprises using Microsoft 365 face a new evasion technique that blends C2 traffic into legitimate cloud API calls, making traditional network monitoring insufficient.
Audit Graph API permissions across your M365 tenant, enable advanced mailbox auditing, and add detection rules for anomalous calendar event patterns.
Attackers are hiding command-and-control traffic inside Microsoft 365 calendar entries, requiring updated cloud monitoring to detect.
Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.
External link — opens at BleepingComputer in a new tab.
More from the Threat Intel Desk
- Attackers conceal phishing lures using invisible Unicode characters1d
- Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication1d
- Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner1d
- Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials2d
- Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain2d