
Malware Turns Microsoft 365 Calendar Into Covert Attack Vector
Security researchers at Group-IB have actually revealed a Windows malware strain that turns Microsoft 365 calendars into hidden channels for getting commands and taking files from targeted companies. The malware part, dubbed HOLLOWGRAPH, abuses the Microsoft Chart API and a compromised Microsoft 365 account to hide command-and-control activity within legitimate cloud communications.
The malware utilizes the jeopardized account’s calendar as what Group-IB called a “two-way dead drop.” Assaulters develop calendar occasions containing encrypted guidelines while HOLLOWGRAPH uploads taken files as attachments to separate events.
Those occasions are set up for May 13, 2050, keeping them far outside the mailbox owner’s typical calendar view. The method enables the malware to interact through Microsoft facilities without connecting directly to an attacker-controlled server for its primary command channel.
HOLLOWGRAPH supports only 2 commands: “get” for obtaining guidelines and “send” for exfiltrating files. The restricted command set recommends the malware runs as one part of a larger collection of tools instead of as a standalone backdoor.
Group-IB connected the malware with high confidence to the Cavern backdoor structure based on resemblances in command syntax and architecture. The firm discovered a minimum of 12 contaminated systems, though just 3 were actively interacting with the assaulter throughout the observation duration.
The earliest communication occurred June 3 and the current was tape-recorded July 9. A jeopardized mail box tied to an Israeli company and malware samples published from Israel show that the campaign has focused mainly on Israeli targets.
The little number of infections suggests the operation is “highly targeted rather than opportunistic,” Group-IB said.
HOLLOWGRAPH likewise preserves a secondary communication approach utilizing Domain Name System tunneling. The malware sends specially constructed IPv6 address inquiries to an attacker-controlled domain to obtain updated Microsoft Entra ID credentials, including the tenant ID, customer ID, customer trick, and mailbox address required to gain access to Microsoft Graph.
Commands and taken information sent through the calendar are secured with RSA and AES encryption. Separate crucial pairs handle inbound guidelines and outgoing files, avoiding direct exposure of one secret from immediately jeopardizing both communication directions.
Group-IB stated it could not confidently associate the campaign to a known threat star. Scientists discovered some technical overlap with Lyceum, an Iranian-linked subgroup of OilRig, however examined that connection with low self-confidence. The targeting and technical design however point to a “capable and well-resourced foe,” the company said.
The project extends a wider trend in which assailants conceal malicious activity behind trusted services and familiar service tools. Current malware operations have abused signed applications, remote management software, and cloud facilities to mix into genuine business activity.
Group-IB advises that security groups keep an eye on Microsoft Chart and mail box audit logs for unusual calendar operations, particularly occasions dated far into the future. Defenders ought to also look for occasions with encrypted text accessories, application-generated subject changes, and the logAzure.txt setup file.
Orgs ought to examine OAuth applications, rotate exposed qualifications and look for abnormally regular IPv6 DNS inquiries or long, high-entropy subdomains that could suggest tunneling activity. For more details, have a look at Group-IB’s complete technical analysis here.