
HollowGraph Malware Abuses Microsoft 365 Calendars and Graph APIs for Covert C2 Operations
CybersecurityMalwareThreatIntelligenceCloudSecurity
Researchers have identified the HollowGraph malware, which leverages Microsoft 365 calendars and Microsoft Graph APIs as a covert command-and-control (C2) channel. The malware has been attributed to the Cavern framework, a previously documented threat infrastructure. HollowGraph abuses legitimate Microsoft 365 services to evade detection by blending malicious traffic with normal calendar and API activity. No specific dates, victim organizations, or technical indicators (e.g., hashes, CVEs) were disclosed in the report. The primary impact involves stealthy C2 communications, potentially enabling data exfiltration or further compromise.