Date: 07/21/2026
Severity: High
Summary
HOLLOWGRAPH is a sophisticated malware that abuses the Microsoft Graph API for covert command-and-control and uses DNS tunneling to refresh cloud authentication tokens, enabling it to blend into legitimate Microsoft 365 and network traffic. Researchers assessed with high confidence that it is linked to the Cavern malware framework and has observed tradecraft similarities with Iranian-nexus activity, although the threat actor remains unattributed. The campaign's advanced evasion techniques and focused targeting of Israeli entities indicate a highly capable and well-resourced adversary.
Indicators of Compromise (IOC) List
Domain/Urls | cloudlanecdn.com |
Hash | 75e51774b8f79e5f256eaae639635f911b3e744d4774fd6068dd980255621509
B3d0f6e4e3be395fd7cf9e8101c89963d77216578cbb117a6ac9bc3564485eff
F3f3006f8304788251b153d53b305322b8acab0c66ec816b8d9f101bcc851da3
|
Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection
Detection Query 1 : | domainname like "cloudlanecdn.com" or url like "cloudlanecdn.com" or siteurl like "cloudlanecdn.com" |
Detection Query 2 : | sha256hash IN ("B3d0f6e4e3be395fd7cf9e8101c89963d77216578cbb117a6ac9bc3564485eff","F3f3006f8304788251b153d53b305322b8acab0c66ec816b8d9f101bcc851da3","75e51774b8f79e5f256eaae639635f911b3e744d4774fd6068dd980255621509")
|
Reference:
https://www.group-ib.com/blog/hollowgraph-microsoft-365/