HollowGraph uses Microsoft 365 calendars as a covert C2 channel
Researchers linked the HollowGraph malware to the Cavern framework after discovering that it uses Microsoft 365 calendars and Microsoft Graph APIs as a hidden command-and-control channel. This choice allows malicious traffic to blend in with perfectly legitimate enterprise activity, making detection more difficult. The fact that malware exploits widely adopted SaaS services shifts the problem from the traditional network perimeter to application and identity telemetry. The case is important because it shows how criminals are turning everyday productivity tools into stealth communication infrastructure. For defenders, monitoring email and endpoints alone is no longer enough if cloud APIs are being used as persistence channels. The direction is clear: the cloud collaboration stack is now also an attack surface.
Source: Infosecurity Magazine


Leave a Reply