HOLLOWGRAPH: .NET NativeAOT Malware Abusing Microsoft Graph API and M365 Calendar Events for C2, Linked to Cavern Manticore/Lyceum (Low Confidence) — Threadlinqs Intelligence
As of 2026-07-21, HOLLOWGRAPH: .NET NativeAOT Malware Abusing Microsoft Graph API and M365 Calendar Events for C2, Linked to Cavern Manticore/Lyceum (Low Confidence) is a high-severity malware threat attributed to Cavern Manticore (Iran), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 42 indicators of compromise.
Threat ID: TL-2026-1553 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
Updated: 2026-07-21 · revalidated 1× · latest source
Attribution: Cavern Manticore · Iran · ESPIONAGE
Group-IB identified HOLLOWGRAPH, a Windows .NET NativeAOT-compiled DLL that abuses the Microsoft Graph API to exfiltrate files and receive attacker commands via Microsoft 365 calendar events dated to
HOLLOWGRAPH is a Windows DLL malware component compiled with .NET NativeAOT, part of a modular toolset that Group-IB assesses shares command-format and plugin-loading overlaps with the Cavern backdoor framework independently profiled by Check Point Research as 'Cavern Manticore' (also tracked historically as 'Cav3rn'). The malware turns a compromised Microsoft 365 mailbox/calendar into a bidirectional dead-drop C2 channel: operators create calendar events dated far in the future (2050-05-13) with subjects encoding a 7-character task ID (e.g. 'Event ID: <taskID>'); the implant polls the Microsoft Graph API for these events, downloads encrypted attachments named File{n}.txt, and decrypts them with an embedded RSA-2048 private key using RSA-OAEP-SHA256 to unwrap an AES-256-GCM session key. To exfiltrate data, the implant encrypts target files with a separate RSA-2048 public key, uploads the ciphertext as File{n}.txt attachments to newly created 2050-dated calendar events, and renames the event subject to a 'Boss{..}ID{..}' format for operator triage. A secondary channel uses DNS tunneling over IPv6 AAAA queries to cloudlanecdn[.]com (via the DnsClient.NET library) to refresh Microsoft Entra ID OAuth2 client-credential parameters (tenantId, clientId, clientSecret, target mailbox) when the primary Graph API token expires, encoding roughly 14 usable bytes per IPv6 response reassembled into UTF-8 data. Configuration (hardcoded Entra ID app registration client ID/secret/tenant ID, target mailbox, and both RSA key pairs) is persisted on disk disguised as a benign log file, logAzure.txt. The technique of using separate RSA key pairs for inbound versus outbound traffic prevents cryptographic correlation of the two data flows, and calendar events dated decades in the future keep the C2 artifacts out of normal calendar UI views. Group-IB assesses the campaign as narrowly and deliberately targeted -- 12 total infected Israeli hosts with only 3 actively communicating during the observation window -- consistent with a disciplined, low-noise espionage operation rather than opportunistic malware distribution. Command-format analysis (underscore-delimited '<command>_;;_<arg0>_,_<arg1>_,_<arg2>' structure, base64-encoded numeric self-commands such as '003' for debug-logging toggle) closely mirrors the Cavern backdoor framework, and Group-IB notes technical overlap with a Lyceum .NET backdoor observed in early 2025 (SHA-256 315bdba98c6fe863d39f6afccc727e17d5aea63bf21259444fa988cae56d61c1) and an earlier Lyceum sample referenced in prior state-sponsored-actor reporting (SHA-256 1573e125197ec77d8e9930c611ba2802ee59e19629396b5e99b426b46c53bd25), but explicitly states it 'cannot confidently attribute this activity to any previously identified threat actor.' Independently, Check Point Research's Cavern Manticore report (published 2026-07-06) documents the same broader framework operating against Israeli IT providers and government targets via multi-hop supply-chain compromise -- moving from an initially compromised IT service provider through a second-hop provider before reaching the intended victim, abusing RMM tooling (e.g. SysAid's legitimate software-deployment feature, with Check Point explicitly stating no SysAid vulnerability was involved) for lateral distribution of malicious 'updates.' The Cavern Manticore toolset spans multiple compilation formats (.NET Framework IL-only, Mixed-Mode C++/CLI, and .NET 8 NativeAOT) used deliberately as an anti-analysis layer to force reverse engineers across differing toolchains, and includes DLL-sideloaded agent (uxtheme.dll), communications (n-HTCommp.dll), file-manager (mhm.dll), SQL browser (db.dll), LDAP/AD-recon (ode.dll), network-recon (n-ten.dll), and SOCKS5/WebSocket tunnel (n-sws.dll) modules sideloaded via a trojanized WinDirStat.exe deployment. Check Point attributes Cavern Manticore to Iran's Ministry of Intelligence and Security (MOIS) with overlap to Lyceum (OilRig sub-group) and MuddyWater trade
Weaknesses (CWE)
CWE-506, CWE-311, CWE-1188
Target sectors: government administration, itservices, telecoms, oilgas, aviation, internetserviceproviders
Target regions: israel, Middle East
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 42 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
Community OSINT corroboration
1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.
MALWARE, HIGH, threat intelligence, cybersecurity, T1195, T1195.002, T1078, T1059, T1204.002, T1047, T1547, T1078.004, T1574.002, T1218.009