HOLLOWGRAPH: Microsoft 365 Calendar-Based C2 Malware Targeting Israeli Organizations (Cavern Manticore)
HOLLOWGRAPH: Microsoft 365 Calendar-Based C2 Malware (TL-2026-1567), also tracked as HollowGraph, is a high-severity malware campaign, first published 2026-07-20. It is attributed to Cavern Manticore (Iran) with medium confidence, affects Microsoft Microsoft 365 / Microsoft Graph API, maps to 27 MITRE ATT&CK techniques (T1001, T1005, T1016), and is covered by 9 detection rules and 30 indicators of compromise.
Key facts for TL-2026-1567
- Threat ID
- TL-2026-1567
- Also known as
- HollowGraph, Cavern backdoor framework campaign
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- 2026-07-20
- Last reviewed
- 2026-07-20
- Attribution
- Cavern Manticore
- Attribution confidence
- MEDIUM
- Nation-state nexus
- Iran
- Motivation
- ESPIONAGE
- Target sectors
- government administration, defense, informationtechnology
- Target regions
- israel, Middle East
- Detection rules
- 9
- Indicators of compromise
- 30
Malware and tooling in HOLLOWGRAPH: Microsoft 365 Calendar-Based C2 Malware
Malware and tooling: Cavern, HOLLOWGRAPH, SysAid RMM software-deployment feature, WinDirStat
A stealthy .NET-compiled malware component dubbed HOLLOWGRAPH abuses the Microsoft Graph API and compromised Microsoft 365/Entra ID accounts to plant covert command instructions and exfiltrate data via calendar events dated 2050-05-13, targeting Israeli organizations in a suspected espionage operation. Group-IB attributes HOLLOWGRAPH with high confidence to the Cavern modular backdoor framework, which Check Point Research ties to an Iran-nexus actor tracked as Cavern Manticore (MOIS-linked), with technical overlap to MuddyWater and a low-confidence link to Lyceum.
How HOLLOWGRAPH: Microsoft 365 Calendar-Based C2 Malware works
HOLLOWGRAPH is a .NET DLL implant that treats the calendar of a compromised Microsoft 365 mailbox as a two-way covert dead drop, wrapping all command-and-control traffic inside legitimate Microsoft Graph API requests so that it blends into ordinary Microsoft 365 application traffic and never contacts an attacker-owned server directly for tasking. The implant supports exactly two commands: 'get' (retrieve operator tasking) and 'send' (exfiltrate stolen data). To pull tasking, HOLLOWGRAPH queries the compromised mailbox's calendar for an event planted by the operator and dated 2050-05-13 -- roughly 24 years in the future -- so the legitimate mailbox owner is unlikely to ever scroll to it. Event subjects follow bare-GUID or 'Event ID:' / 'Boss{..}ID{..}' naming patterns, and instructions are read from an attached File{n}.txt-style attachment. To exfiltrate, the malware reverses the process: it encrypts the stolen file, creates its own far-future calendar event, and uploads the data as one or more attachments. All calendar-borne communications are secured with a hybrid RSA + AES-256-GCM encryption scheme, using distinct RSA key pairs for inbound tasking versus outbound exfiltration.
A secondary channel supports credential refresh: HOLLOWGRAPH performs DNS tunneling over IPv6 AAAA record queries to the attacker domain cloudlanecdn[.]com, extracting roughly 14 usable payload bytes per 16-byte IPv6 address, reassembling multiple query responses into a UTF-8 payload that updates locally cached Entra ID (Azure AD) credential material. This DNS channel is unencrypted, unlike the calendar channel. A local artifact, logAzure.txt, disguises stored credentials and encryption key material as a routine Azure logging file.
Group-IB ties HOLLOWGRAPH to the Cavern framework with high confidence based on shared command syntax and matching internal tasking structure, but states it cannot confidently attribute the campaign to a previously identified threat actor at high confidence. Check Point Research separately documented Cavern -- a modular, three-format .NET backdoor framework (standard .NET Framework IL, Mixed-Mode C++/CLI, and .NET 8 NativeAOT) -- and attributed it to an Iran-nexus, Ministry of Intelligence and Security (MOIS)-linked cluster it calls Cavern Manticore, which overlaps technically with the known Iranian actors MuddyWater and OilRig's Lyceum subgroup. In a related, separately reported intrusion, Cavern Manticore abused the legitimate software-deployment feature of an already-compromised SysAid RMM instance (no SysAid vulnerability was involved) to push a DLL-sideloading package -- WinDirStat.exe alongside a trojanized uxtheme.dll (the Cavern Agent) -- to a second host inside the same victim network, from which additional Cavern modules (n-HTCommp.dll for HTTPS/WebSocket transport, mhm.dll for file operations and DPAPI credential decryption, db.dll for SQL database enumeration, ode.dll for LDAP/AD reconnaissance and brute-force, n-ten.dll for network/SMB reconnaissance, n-sws.dll for SOCKS5/WebSocket tunneling) were deployed on demand. Cavern's C2 infrastructure is registered through the Iranian hosting/registrar Fars Data, with domains including hospitalinstallation[.]com and its subdomains auth.hospitalinstallation[.]com and google.com.hospitalinstallation[.]com (the latter using a lookalike subdomain for visual obfuscation), plus legacy infrastructure adserviceupdate[.]com and hygienehistory[.]com. Group-IB observed at least 12 infected systems, three of them actively communicating with the operator, across a campaign window running from 3 June to 9 July 2026, consistent with a small, selective footprint indicative of targeted espionage rather than opportunistic crime.
MITRE ATT&CK techniques used in TL-2026-1567
Command and Control
T1001 Data Obfuscation; T1071 Application Layer Protocol; T1090 Proxy; T1095 Non-Application Layer Protocol; T1102 Web Service; T1573 Encrypted Channel
Collection
T1005 Data from Local System; T1119 Automated Collection; T1560 Archive Collected Data
Discovery
T1016 System Network Configuration Discovery; T1046 Network Service Discovery; T1087 Account Discovery; T1135 Network Share Discovery
Lateral Movement
T1021 Remote Services; T1570 Lateral Tool Transfer
Defense Evasion
T1027 Obfuscated Files or Information; T1078 Valid Accounts; T1140 Deobfuscate/Decode Files or Information; T1574 Hijack Execution Flow
Exfiltration
T1041 Exfiltration Over C2 Channel; T1048 Exfiltration Over Alternative Protocol
Execution
T1072 Software Deployment Tools
Initial Access
T1078 Valid Accounts; T1199 Trusted Relationship; T1566 Phishing
Credential Access
T1110 Brute Force; T1555 Credentials from Password Stores
Persistence
T1547 Boot or Logon Autostart Execution
stealth
Affected products and versions in HOLLOWGRAPH: Microsoft 365 Calendar-Based C2 Malware
- Microsoft — Microsoft 365 / Microsoft Graph API
Vulnerable versions: cloud service - all tenants with compromised credentials - Microsoft — Microsoft Entra ID (Azure AD)
Vulnerable versions: cloud service - accounts with compromised credentials - SysAid — SysAid RMM (software-deployment feature abused, not exploited)
Vulnerable versions: N/A - legitimate feature abuse, no vulnerability involved - WinDirStat — WinDirStat.exe
Vulnerable versions: all versions - abused for DLL sideloading via uxtheme.dll
Remediation for HOLLOWGRAPH: Microsoft 365 Calendar-Based C2 Malware
Immediate actions
- Block the C2 domains cloudlanecdn[.]com, hospitalinstallation[.]com, auth.hospitalinstallation[.]com, google.com.hospitalinstallation[.]com, adserviceupdate[.]com, and hygienehistory[.]com at DNS/perimeter
- Hunt Microsoft 365 / Microsoft Graph audit logs for calendar events dated far in the future (e.g. 2050-05-13) with bare-GUID or 'Event ID:' / 'Boss{..}ID{..}' subjects and File{n}.txt-pattern attachments
- Audit OAuth client-credential and app-registration grants against Microsoft Graph API for anomalous calendar/mail scopes
- Search endpoints for logAzure.txt and config.txt artifacts and for uxtheme.dll loaded outside its legitimate Windows theming context
- Isolate hosts showing WinDirStat.exe spawned from an RMM/software-deployment tool followed by unexpected DLL loads
Workarounds
- Disable or tightly scope legacy OAuth app permissions with Calendars.ReadWrite / Mail.Read Graph scopes pending investigation
- Restrict SysAid (or equivalent RMM) software-deployment jobs to signed, allow-listed packages only
Longer-term hardening
- Deploy EDR with behavioral detection for anomalous AppDomain loads and .NET NativeAOT execution in non-development contexts
- Implement Conditional Access policies and MFA hardening for Microsoft 365 / Entra ID accounts, particularly for accounts with calendar-sharing or delegate access
- Restrict and monitor RMM/software-deployment platform features (remote file push, remote printing, clipboard, file transfer) with least-privilege access to deployment consoles
- Establish continuous outbound DNS monitoring for high-volume AAAA queries to single domains with high-entropy subdomain labels (DNS tunneling detection)
Weaknesses (CWE) in HOLLOWGRAPH: Microsoft 365 Calendar-Based C2 Malware
CWE-506, CWE-311, CWE-693
Timeline of HOLLOWGRAPH: Microsoft 365 Calendar-Based C2 Malware
- Cavern Manticore emerges as a tracked cluster with focused campaigns in early 2026, per Check Point Research / GBHackers reporting on the Cavern framework's origin (approximate date; sources cite 'early 2026' without a specific day).
- Group-IB observes earliest active HOLLOWGRAPH victim traffic; campaign window begins.
- Rescana publishes an active-exploitation alert on Cavern Manticore's abuse of SysAid's software-deployment feature to push the trojanized WinDirStat/uxtheme.dll DLL-sideloading package.
- Rescana issues a correction to its SysAid alert, clarifying that Cavern Manticore had already gained access to the victim environment before abusing SysAid's legitimate software-deployment feature -- no SysAid vulnerability was involved.
- Last observed active HOLLOWGRAPH victim C2 communication between a compromised mailbox and the attackers, closing the ~5-week observation window (3 June - 9 July 2026).
- Cyber Security News, The Hacker News, BleepingComputer, Infosecurity Magazine, The Register, and WindowsNews.ai publish coverage of the HOLLOWGRAPH findings, targeting Israeli organizations.
- Group-IB publicly discloses HOLLOWGRAPH, its Microsoft Graph API calendar-based C2 mechanism, and its high-confidence linkage to the Cavern backdoor framework.
- Date used by HOLLOWGRAPH operators for planted calendar-event dead-drops, chosen roughly 24 years in the future to avoid discovery by the legitimate mailbox owner.
Sources cited for HOLLOWGRAPH: Microsoft 365 Calendar-Based C2 Malware
- Hackers Weaponizing Microsoft 365 Calendar Invites Into Malware
- HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050
- New HollowGraph malware uses Microsoft Graph for stealthy C2 comms
- New HollowGraph Malware Hijacks Microsoft 365 Calendars for Covert C2
- Microsoft 365 calendars become spy drop boxes in HOLLOWGRAPH campaign
- HOLLOWGRAPH: Attackers Turn Outlook Calendar Into a Secret Command Channel
- Cavern Manticore: Exposing Iran-Linked Modular C2 Framework
- From Graph API to Tor, malware gets creative with C2
- Cavern Manticore Malware Uses Low-Detection .NET Modules for Reconnaissance and Lateral Movement
- Active Exploitation Alert: Iranian Cavern Manticore APT Abuses SysAid Supply Chain With Modular Cavern C2 Malware Targeting Israeli Organizations
Threats related to HOLLOWGRAPH: Microsoft 365 Calendar-Based C2 Malware
- HollowGraph Malware Abuses Microsoft 365 Calendar as Covert C2 Channel (Cavern Framework, Suspected Cavern Manticore / Iran MOIS-Nexus)
- HOLLOWGRAPH: .NET NativeAOT Malware Abusing Microsoft Graph API and M365 Calendar Events for C2, Linked to Cavern Manticore/Lyceum (Low Confidence)
- HollowGraph Malware Abuses Microsoft 365 Calendars for Covert C2 via Graph API
- Project CAV3RN / Cavern Manticore: Iran-Linked Modular Cyberespionage Framework Abuses Outlook Calendar (Microsoft Graph API) and DNS AAAA Records for C2 and Credential Recovery
- Cavern Manticore: Iran-Linked Modular .NET C2 Framework Targeting Israeli Government and IT Sectors via SysAid RMM Abuse
- Cavern Manticore's CAV3RN C2 Framework Adds DNS-Based Channel Selection and Google Apps Script Relay
Detection coverage for TL-2026-1567
As of 2026-07-20, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1567 across Splunk SPL, Microsoft KQL and Sigma, covering 30 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.
Community OSINT corroboration for TL-2026-1567
1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.