HollowGraph usa i calendari Microsoft 365 come canale C2 covert

HollowGraph uses Microsoft 365 calendars as a covert C2 channel

Researchers linked the HollowGraph malware to the Cavern framework after discovering that it uses Microsoft 365 calendars and Microsoft Graph APIs as a hidden command-and-control channel. This choice allows malicious traffic to blend in with perfectly legitimate enterprise activity, making detection more difficult. The fact that malware exploits widely adopted SaaS services shifts the problem from the traditional network perimeter to application and identity telemetry. The case is important because it shows how criminals are turning everyday productivity tools into stealth communication infrastructure. For defenders, monitoring email and endpoints alone is no longer enough if cloud APIs are being used as persistence channels. The direction is clear: the cloud collaboration stack is now also an attack surface.

Source: Infosecurity Magazine

Leave a Reply

Your email address will not be published. Required fields are marked *


Post Comment