Top Tweets for #HollowGraph
Discover how the HollowGraph malware exploits Microsoft 365 calendars for C2 communication and data exfiltration in targeted espionage attacks.
#HollowGraph #Microsoft365 #Malware #CyberEspionage #InfoSec #GroupIB
https://t.co/WY6SXomPnM
#ThreatProtection #HollowGraph #malware leverages Microsoft 365 Calendar events for C2 communication, read more about Symantec's protection: https://t.co/3m9iM6Dj8B
🚨 Threat actors continue to find new ways to hide malicious activity inside trusted enterprise services.
Group-IB Threat Intelligence researchers have uncovered #HOLLOWGRAPH, a Windows malware linked with high confidence to the Cavern framework that abuses Microsoft Graph API and compromised #Microsoft365 accounts to establish a covert command-and-control channel.
Key findings from our research:
🔹 Microsoft 365 calendars repurposed as two-way dead drops for command execution and data exfiltration
🔹 Commands and stolen files hidden inside encrypted calendar event attachments scheduled for the year 2050
🔹 DNS tunneling over IPv6 AAAA records used to refresh Microsoft Entra ID credentials required for cloud-based C2 communications
🔹 At least 12 identified victims, with telemetry suggesting a highly targeted operation focused on Israeli entities
🔹 Technical overlaps linking HOLLOWGRAPH to the broader Cavern framework
As threat actors increasingly leverage legitimate cloud infrastructure to evade detection, defenders must expand visibility beyond traditional network indicators and monitor for abuse of trusted services.
Read the full technical analysis: https://t.co/03zw7zjFUH
#ThreatIntelligence #CyberSecurity #MalwareAnalysis #CloudSecurity

Instead of using traditional C2 infrastructure, #HOLLOWGRAPH stores operator tasking and stolen data inside calendar events scheduled for 13 May 2050. The implant retrieves commands from encrypted attachments and uploads exfiltrated files back to the same mailbox as File{n}.txt attachments, using separate RSA key pairs and AES-256-GCM encryption for each communication direction. Defenders should hunt for calendar events with Event ID: <taskid> {} subjects or the Boss{}ID{} naming convention. #ThreatIntel #APT

#HOLLOWGRAPH is a newly identified Windows malware linked with high confidence to the Cavern framework. The #malware abuses Microsoft Graph API and a compromised #Microsoft365 mailbox, transforming the victim's calendar into a two-way dead drop for command-and-control and data exfiltration while blending malicious traffic into legitimate Microsoft cloud communications. #CyberSecurity


Last Seen Hashtags on Sotwe
Most Popular Users

Elon Musk 
@elonmusk
241.3M followers

Barack Obama 
@barackobama
119.1M followers

Cristiano Ronaldo 
@cristiano
113.1M followers

Donald J. Trump 
@realdonaldtrump
111.8M followers

Narendra Modi 
@narendramodi
107.1M followers

Rihanna 
@rihanna
98.3M followers

NASA 
@nasa
92.3M followers

Justin Bieber 
@justinbieber
91.5M followers

KATY PERRY 
@katyperry
89.1M followers

Taylor Swift 
@taylorswift13
83.1M followers

Lady Gaga 
@ladygaga
74.5M followers

Virat Kohli 
@imvkohli
72.1M followers

Kim Kardashian 
@kimkardashian
70.5M followers

YouTube 
@youtube
68.8M followers

Neymar Jr 
@neymarjr
65M followers

Bill Gates 
@billgates
64.7M followers

The Ellen Show
@theellenshow
62.4M followers

Selena Gomez 
@selenagomez
62.2M followers

CNN 
@cnn
61.8M followers

X 
@x
60.8M followers







