A stealthy new malware strain called HOLLOWGRAPH that hijacks Microsoft 365 calendars to secretly communicate with hackers, disguising malicious commands as ordinary calendar invites. HOLLOWGRAPH is a .NET-compiled malware component that abuses the Microsoft Graph API through a compromised Microsoft 365 account, turning the mailbox’s calendar into a covert two-way “dead drop” for hackers. The malware supports only two commands, get and send, and instead of contacting a suspicious attacker server, it routes everything through trusted Microsoft cloud infrastructure, making the traffic blend in with normal business activity. According to a Group-IB report, the operators plant instructions as calendar events, while...
Read the full article at the source.
Comments (0)
No comments yet. Be the first to comment!