A new malware named HollowGraph has been identified as exploiting Microsoft 365 calendars for command-and-control communications, according to cybersecurity firm Group-IB. This malware is believed to be linked to the Iran-affiliated threat group Cavern Manticore, as detailed by Check Point earlier this month. HollowGraph cleverly integrates with the Microsoft Graph API, using a compromised 365 account in Israel to mask its C&C communications within typical network traffic.

Group-IB reports that the malware uses the Microsoft Graph API to transform the compromised mailbox's calendar into a two-way communication channel. Operators implant task directives as calendar events, while the malware extracts stolen data by creating its own events with encrypted attachments. To remain undetected, these events are dated far into the future. The malware employs a mix of RSA and AES encryption to protect its payloads.

Furthermore, HollowGraph maintains a secondary communication line through DNS tunneling for configuration updates and utilizes Microsoft Entra ID credentials for authentication. Group-IB has identified twelve victims, with three actively interacting with the attackers' infrastructure. The earliest identified communication traces back to June 3, suggesting the malware has been active since at least last month.

The malware operates without direct contact to attacker-controlled servers for payload delivery. Instead, it uses two commands: 'send' for creating calendar events with file attachments, and 'get' for retrieving new instructions. Its hardcoded configuration includes various identifiers and keys, stored in a file upon execution.

While Group-IB suspects a connection to the Lyceum subgroup of the OilRig group linked to Iran MOIS, the attribution is made with low confidence due to insufficient unique identifiers. Technical similarities were noted with Lyceum, but they were not distinct enough to draw a definitive conclusion.