New HollowGraph Trojan Leverages Microsoft Graph API and Calendar Functions
Security firm Group-IB has identified a new malware dubbed HollowGraph that utilizes Microsoft Graph API and Microsoft 365 calendar features to create covert communication channels.

Cybersecurity firm Group-IB has disclosed the emergence of a new malware variant named HollowGraph. This trojan leverages Microsoft Graph API and Microsoft 365 calendar functionalities to establish covert command and control (C2) channels with attacker-controlled servers.
HollowGraph supports basic commands such as "get" and "send." Attackers can combine these with Microsoft 365 calendar features to modify pre-existing calendar events via the Graph API. This allows for the execution of specific tasks or the delivery of malicious attachments at designated times.
Group-IB noted that the instruction format used by HollowGraph shows significant similarity to the previously discovered Cavern modular backdoor framework, suggesting it may be a variant of that framework.
Researchers advise organizations to enhance their monitoring of Microsoft Graph API call logs and Microsoft 365 mailbox audit logs. Key indicators to watch for include abnormally created calendar events, suspicious attachment uploads, and unusual modifications to email subject fields to detect potential malicious activity.