2 min read

Spy malware hides in Microsoft 365 calendars

Group-IB says HOLLOWGRAPH used Microsoft 365 calendars as covert command-and-control, hiding tasks and stolen files in events dated May 13, 2050.

Image: The Register

Microsoft 365 calendars are the latest covert channel for espionage malware. According to Group-IB, a malware component it calls HOLLOWGRAPH used a compromised Microsoft 365 calendar to receive commands and stash stolen files, with both hidden inside appointments set 24 years into the future.

Instead of talking to a traditional command-and-control server, the implant searched calendar events for encrypted tasking and created new events containing exfiltrated data for operators to retrieve later. Every event created by HOLLOWGRAPH was dated May 13, 2050, which Group-IB described as an otherwise empty stretch of a user’s calendar where encrypted attachments would be less likely to draw attention.

The trick is not an exploit in Microsoft Graph or Microsoft 365. The malware used legitimate Graph API requests so its traffic blended in with normal Microsoft 365 app activity. Group-IB said the implant itself was relatively small and mainly handled three jobs:

Recommended reading

2 Million Cars May Hide a Hackable KARR Device

  • fetching instructions from one calendar event
  • storing stolen files in another
  • retrieving fresh Entra ID credentials through a DNS tunneling channel so Graph-based communications could continue

Group-IB linked HOLLOWGRAPH to the Cavern framework with high confidence, citing matching command formats and other implementation details. The firm also found similarities to the Iranian-linked espionage group Lyceum, but said that connection was supported with only low confidence.

“HOLLOWGRAPH represents an advanced and highly targeted espionage threat.” “By abusing trusted Microsoft 365 calendars through the Microsoft Graph API and refreshing its cloud authentication credentials through DNS tunneling, the malware conceals its command-and-control within legitimate Microsoft 365 and network traffic, evading conventional perimeter defenses.”

Group-IB

The campaign appears to have been tightly focused. Group-IB identified 12 infected systems, but only three communicated with the compromised mailbox during the period researchers observed. The mailbox used for command-and-control belonged to an Israeli organization, malware samples were uploaded from Israel, and Group-IB said the evidence points to a targeted espionage operation rather than a broad criminal campaign.

What makes the operation notable is precisely what it did not do: it did not exploit a software flaw. It abused services that most organizations already trust, making the activity much harder to spot than malware reaching out to attacker-run infrastructure.

Sophia Reynolds

Security Editor

Sophia unpacks the invisible wars happening on our networks. Covering cybersecurity, privacy legislation, and cryptography, she exposes how our data is weaponized and defended. Before joining for(geeks), she spent years as a penetration tester. She's the reason the rest of the team uses physical security keys.

via The Register

// Keep reading