HOLLOWGRAPH: Turning Microsoft 365 Calendars into Covert Command-and-Control Channels

    Date: 07/21/2026

    Severity: High

    Summary

    HOLLOWGRAPH is a sophisticated malware that abuses the Microsoft Graph API for covert command-and-control and uses DNS tunneling to refresh cloud authentication tokens, enabling it to blend into legitimate Microsoft 365 and network traffic. Researchers assessed with high confidence that it is linked to the Cavern malware framework and has observed tradecraft similarities with Iranian-nexus activity, although the threat actor remains unattributed. The campaign's advanced evasion techniques and focused targeting of Israeli entities indicate a highly capable and well-resourced adversary.

    Indicators of Compromise (IOC) List

    Domain/Urls

    cloudlanecdn.com

    Hash

    75e51774b8f79e5f256eaae639635f911b3e744d4774fd6068dd980255621509

    B3d0f6e4e3be395fd7cf9e8101c89963d77216578cbb117a6ac9bc3564485eff

    F3f3006f8304788251b153d53b305322b8acab0c66ec816b8d9f101bcc851da3

    Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection

    Detection Query 1 :

    domainname like "cloudlanecdn.com" or url like "cloudlanecdn.com" or siteurl like "cloudlanecdn.com"

    Detection Query 2 :

    sha256hash IN ("B3d0f6e4e3be395fd7cf9e8101c89963d77216578cbb117a6ac9bc3564485eff","F3f3006f8304788251b153d53b305322b8acab0c66ec816b8d9f101bcc851da3","75e51774b8f79e5f256eaae639635f911b3e744d4774fd6068dd980255621509")

    Reference: 

    https://www.group-ib.com/blog/hollowgraph-microsoft-365/ 


    Tags

    MalwareThreat ActorDNS tunnelingIranIsraelMicrosoftCloud Infrastructure

    « Previous ArticleNext Article »

    Comments

    No records to display

    Looking for Something?
    Threat Research Categories:
    Tags