New HollowGraph Malware Abuses Microsoft 365 Calendar for C&C Communication

  Rassegna Stampa, Security
image_pdfimage_print

A recently discovered piece of malware abuses the Microsoft 365 calendar for command-and-control (C&C) communication, Group-IB reports.

Dubbed HollowGraph, the malware is believed to be part of a larger toolkit and is likely linked to Cavern Manticore, an Iran-nexus threat actor that Check Point detailed earlier this month.

The malware’s communication mechanism relies on the Microsoft Graph API and a compromised 365 account in Israel to hide its C&C communication within legitimate traffic.

“Using the Microsoft Graph API, it treats the compromised mailbox’s calendar as a two-way dead-drop: operators plant tasking as calendar events, and the implant exfiltrates stolen files by creating its own events with encrypted data attached,” Group-IB explains.

The payloads are attached to events as files, and the events are dated far in the future (13 May 2050) to avoid alerting the mailbox owner. The malware uses hybrid RSA + AES encryption to secure the payloads.

Additionally, HollowGraph retains a secondary communication channel, performing DNS tunneling to refresh its configuration and Microsoft Entra ID (Azure AD) credentials it uses for authentication.

Advertisement. Scroll to continue reading.

Group-IB identified 12 HollowGraph victims, including three that were actively communicating with the attackers’ infrastructure. The earliest observed communication occurred on June 3, suggesting that the malware has been deployed in attacks since at least last month.

“The recovered indicators — an Israeli mailbox used for exfiltration and malware samples uploaded from Israel — suggest a focused interest in Israeli entities rather than broad, opportunistic compromise,” the company notes.

HollowGraph never reaches out to an attacker-controlled server for payload delivery. Instead, it relies on two supported commands: ‘send’ to generate calendar appointments with attached files, and ‘get’ to search for appointments planted by the operator and download new instructions.

The malware’s hardcoded configuration, which contains the Microsoft Entra ID tenant ID, client ID and secret, target mailbox address, C&C domain, and two RSA keys, is written to disk as logAzure.txt upon execution.

Based on command format and structure, Group-IB believes that HollowGraph is part of a variant of the Cavern framework, but attributes it to the Iran MOIS-linked OilRig subgroup Lyceum (also known as Hexane and SiameseKitten) with low confidence.

“Based on the evidence currently available, we cannot confidently attribute this activity to any previously identified threat actor. However, our analysis identified several technical similarities with the Iranian-nexus threat actor Lyceum. While these overlaps are noteworthy, they are not sufficiently unique to support a high-confidence attribution,” Group-IB notes.

Related: In Other News: Iran Tracks US Military Phones, CrashStealer macOS Malware, CVD Blueprint

Related: China-Linked APT GopherWhisper Abuses Legitimate Services in Government Attacks

Related: Multiple Jscrambler Packages Impacted by Supply Chain Attack

Related: GigaWiper Combines Multiple Malware for System-Level Sabotage

https://www.securityweek.com/new-hollowgraph-malware-abuses-microsoft-365-calendar-for-cc-communication/