HollowGraph Malware Abuses Microsoft Graph API and M365 Calendar Events (Future-Dated 2050) for Stealthy Command-and-Control — Threadlinqs Intelligence
As of 2026-07-20, HollowGraph Malware Abuses Microsoft Graph API and M365 Calendar Events (Future-Dated 2050) for Stealthy Command-and-Control is a high-severity malware threat attributed to Cavern Manticore (Iran), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 15 indicators of compromise.
Threat ID: TL-2026-1561 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
Attribution: Cavern Manticore · Iran · ESPIONAGE
HollowGraph is a .NET DLL espionage implant that abuses compromised Microsoft 365 mailbox credentials and the Microsoft Graph API to run a covert command-and-control channel through calendar events
HollowGraph is a newly documented .NET DLL-based espionage implant discovered by Group-IB that weaponizes legitimate, trusted Microsoft 365 infrastructure as a command-and-control (C2) dead drop, requiring no exploited vulnerability -- only a compromised mailbox account and Microsoft Graph API access. The malware authenticates to the Microsoft Graph API using stolen Microsoft 365 mailbox credentials (Entra ID tenant ID, application/client ID, and client secret) and then uses the target mailbox's Calendar feature as a covert two-way communication channel. The operator plants tasking inside calendar events deliberately future-dated to 2050-05-13, with a fixed retrieval/activity window of 22:00-23:00 UTC on that date, so that the implant's beaconing traffic and the associated calendar objects blend into ordinary, rarely-audited M365 activity and evade time-based detection heuristics. Two commands are supported: GET, in which the implant searches the calendar for operator-planted events (subject patterns such as 'Event ID: <7-char-taskID>' or bare GUIDs), downloads the attached tasking, and decrypts it; and SEND, in which the implant creates new calendar events (subject pattern 'Boss{..}ID{..}') with encrypted stolen data attached as files named in a 'File{n}.txt' pattern for exfiltration. All Graph-channel payloads are protected with a hybrid RSA + AES-256-GCM encryption scheme using two distinct RSA key pairs -- one per communication direction (inbound tasking vs. outbound exfiltrated data) -- so that operator and implant traffic cannot be decrypted by intercepting a single key. A secondary, unencrypted DNS-tunneling channel is used strictly for credential refresh: the implant issues DNS queries for IPv6 AAAA records against the attacker-registered domain cloudlanecdn[.]com, and each returned IPv6 address is used to smuggle 14 usable payload bytes, which are reassembled to deliver updated Microsoft Entra ID credentials (tenant ID, client ID, client secret, target mailbox address) and the C2 domain itself. All configuration state -- credentials, RSA keys, C2 domain, mailbox target -- is persisted locally to a file named logAzure.txt, styled to blend in among legitimate Azure/Entra logging artifacts. Group-IB observed at least 12 infected systems, of which 3 were actively communicating with the C2 infrastructure between June 3, 2026 and July 9, 2026, indicating a small, deliberately narrow, highly targeted operation rather than a mass-scale campaign; targeting is assessed to be focused on an organization in Israel, consistent with an espionage rather than financially motivated objective. On the command syntax, Group-IB matched the implant's tasking format (compact key-value strings such as '{"cid": "oXhLaJ0ZvtPb9XB", "type": "self", "cmd": "003_;;__,_"}' and command codes such as base64 'MzU=' decoding to '003', a debug-logging toggle) to the previously catalogued Cavern backdoor framework with high confidence, attributing infrastructure overlap to the Cavern Manticore cluster, which is separately assessed by other researchers as linked to Iran's Ministry of Intelligence and Security (MOIS) and to share tradecraft with MuddyWater and Lyceum/OilRig-adjacent operators. A weaker, low-confidence technical overlap was additionally noted between HollowGraph and Lyceum (aka HEXANE, Siamesekitten, Spirlin, Chrono Kitten, MarnanBridge), an Iranian-nexus espionage group active since at least 2017 against energy, telecom, aviation, ISP, and government targets in the Middle East and Africa, previously known for DNS-based backdoors (DanBot, DnsSystem, Milan, Kevin, Shark) and use of the open-source tools Empire, Mimikatz, and PoshC2. Group-IB explicitly states it cannot confidently attribute HollowGraph to any single previously identified threat actor. Because the abuse relies entirely on legitimate Graph API functionality and valid (stolen) OAuth/Entra ID credentials rather than a software vulnerability, no vendor patch applies; defensive gui
Target sectors: government administration, critical-infrastructure-adjacent unconfirmed israel-based organization
Target regions: israel, Middle East
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 15 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, HIGH, threat intelligence, cybersecurity, T1078.004, T1059, T1098.001, T1027, T1550.001, T1036.005, T1528, T1552.001, T1526, T1074.002