ShellCodeX
Tools • Events • News • Insights
ShellCodeX Intelligence Brief
HIGH Cybersecurity

HollowGraph malware uses Microsoft Graph calendar data for C2

Source headline: New HollowGraph malware uses Microsoft Graph for stealthy C2 comms

Threat level High
Signal strength 70/100
Source confidence 1 source
Published 12 hours ago

Intelligence Summary

Researchers report a malware component called HollowGraph that uses Microsoft Graph to blend C2 traffic into legitimate Microsoft 365 activity. It leverages the calendar feature in compromised mailboxes to receive attacker commands. The same mechanism is used to exfiltrate stolen information back to the attackers. Because the traffic can resemble normal calendaring activity, detection may be more difficult. Microsoft 365 administrators should review mailbox behavior and Graph API access patterns for anomalies.

Recommended Action

Review affected assets, schedule urgent remediation, and monitor related indicators.

Topics

#command-and-control #microsoft-365 #c2-evasion #microsoft-graph #calendar-based-communications #hollowgraph
Original reporting BleepingComputer New HollowGraph malware uses Microsoft Graph for stealthy C2 comms
Open original source