The PolySwarm Blog

Analyze suspicious files and URLs, at scale, millions of times per day. Get real-time threat intel from a crowdsourced network of security experts and antivirus companies competing to protect you.

HOLLOWGRAPH: The New Face of Cloud-Based Espionage

Jul 24, 2026 2:46:49 PM / by The Hivemind

HOLLOWGRAPH2026Regions Targeted: Israel
Related Families: HOLLOWGRAPH, Cavern Framework

 

Executive Summary

Industry researchers identified HOLLOWGRAPH, a newly discovered malware component that it attributes with high confidence to the Cavern backdoor framework. Rather than relying on traditional command-and-control (C2) infrastructure, HOLLOWGRAPH abuses the Microsoft Graph API to transform a compromised Microsoft 365 calendar into a covert communications channel for receiving commands and exfiltrating stolen data. The campaign appears highly targeted, with at least 12 identified victims, primarily Israeli organizations, and only a small subset actively communicating with attacker infrastructure, suggesting a disciplined espionage operation.

Key Takeaways

  • Industry researchers identified HOLLOWGRAPH, a new malware component linked with high confidence to the Cavern backdoor framework.
  • HOLLOWGRAPH abuses the Microsoft Graph API, using compromised Microsoft 365 calendars as covert C2 channels and hiding malicious events in the year 2050.
  • The malware uses DNS tunneling to refresh Microsoft Entra ID credentials while protecting Graph communications with hybrid RSA and AES encryption.
  • At least 12 systems were compromised, with observed activity suggesting a highly targeted espionage campaign focused primarily on Israeli organizations.
  • The campaign highlights the growing trend of adversaries abusing trusted cloud services to conceal C2 traffic and evade conventional network-based detection.

Background

HOLLOWGRAPH represents an evolution in cloud-native malware tradecraft by embedding malicious communications within trusted Microsoft 365 services instead of relying on attacker-controlled infrastructure. This approach enables adversaries to blend malicious activity into legitimate enterprise traffic, significantly complicating detection efforts.

The malware communicates exclusively through Microsoft Graph API requests to a compromised Microsoft 365 mailbox. Operators store commands inside calendar events, while the implant uploads encrypted stolen data as calendar attachments. All events are intentionally scheduled for 13 May 2050, reducing the likelihood that legitimate users will notice the malicious entries.

Group-IB identified at least 12 compromised systems, although only approximately three victims were actively exchanging data with attacker infrastructure during the observation period. Combined with the Israeli infrastructure involved in the operation, these findings suggest a focused cyber espionage campaign rather than broad opportunistic malware deployment.

Technical Analysis

HOLLOWGRAPH is a .NET NativeAOT-compiled DLL that supports only two commands:

  • get – Retrieves encrypted operator tasking from Microsoft 365 calendar events.
  • send – Encrypts and uploads stolen files back into the compromised mailbox as calendar attachments.

Rather than communicating with conventional C2 servers, the malware leverages the Microsoft Graph API to perform every stage of command retrieval and data exfiltration. Operators create specially crafted calendar appointments containing encrypted payloads, while infected systems upload encrypted files as attachments before renaming calendar events using attacker-defined naming conventions.

Communications are protected using a hybrid cryptographic implementation combining RSA-OAEP with AES-256-GCM, with separate RSA key pairs used for inbound tasking and outbound data exfiltration. This separation helps isolate command and exfiltration channels while protecting intercepted traffic from straightforward analysis.

The malware also employs a secondary communications channel using DNS tunneling. Instead of issuing Graph API requests to refresh Microsoft Entra ID credentials, HOLLOWGRAPH performs specially formatted IPv6 AAAA DNS queries against the attacker-controlled domain cloudlanecdn[.]com, allowing operators to update Azure authentication credentials stored locally within a configuration file named logAzure.txt.

Attribution

Group-IB links HOLLOWGRAPH with high confidence to the Cavern framework based on multiple technical similarities, including identical command structures, task formatting, and observed command syntax. Specifically, recovered commands match previously documented Cavern functionality, including self-management instructions used by the framework.

Researchers also identified similarities between Cavern and malware previously associated with the Iranian-linked threat actor Lyceum (also known as a subgroup of OilRig). However, Group-IB emphasizes that these overlaps are insufficient to support definitive attribution, assessing any relationship to Lyceum with low confidence. This cautious attribution highlights the importance of distinguishing between shared development techniques and confirmed operational control.

Significance

While attackers have abused legitimate cloud services for C2 in previous campaigns, HOLLOWGRAPH demonstrates a particularly sophisticated implementation by embedding communications entirely within Microsoft 365 calendar activity. Unlike traditional malware that contacts attacker-owned infrastructure, HOLLOWGRAPH generates activity that closely resembles legitimate Microsoft Graph API traffic. Combined with DNS-based credential refresh and the use of trusted Microsoft services, this significantly reduces reliance on infrastructure that defenders commonly monitor or block. The campaign illustrates a broader trend toward identity-centric and cloud-native intrusion techniques that prioritize stealth over complexity.

Analyst Commentary

HOLLOWGRAPH reflects an increasingly common shift away from traditional malware communications toward abuse of trusted cloud ecosystems. Rather than attempting to evade security controls through encryption alone, modern espionage campaigns increasingly hide malicious activity within services organizations already trust and rely upon every day.

Microsoft Graph API abuse presents a particularly challenging problem because many organizations allow Graph traffic by default to support Microsoft 365 functionality. Calendar modifications, attachment uploads, and OAuth application activity often generate little security scrutiny compared to outbound connections to suspicious domains. For defenders, this reinforces the importance of monitoring cloud identities, OAuth applications, Microsoft Graph API usage, and Microsoft 365 audit logs alongside traditional endpoint and network telemetry. Calendar events scheduled far into the future, unexpected application-driven attachment uploads, and anomalous Graph API activity may all represent valuable detection opportunities.

PolySwarm can provide additional value by identifying malware associated with emerging cloud-centric intrusion campaigns before traditional signatures mature. Combining multi-engine malware analysis with threat intelligence enables analysts to rapidly investigate novel malware families such as HOLLOWGRAPH while enriching detections with broader campaign context.

IOCs

PolySwarm has multiple samples of HOLLOWGRAPH.

 

75e51774b8f79e5f256eaae639635f911b3e744d4774fd6068dd980255621509

F3f3006f8304788251b153d53b305322b8acab0c66ec816b8d9f101bcc851da3

B3d0f6e4e3be395fd7cf9e8101c89963d77216578cbb117a6ac9bc3564485eff

 

Click here to view all samples of HOLLOWGRAPH in our PolySwarm portal.

 

Don’t have a PolySwarm account? Go here to sign up for a free Community plan or subscribe.

Contact us at hivemind@polyswarm.io | Check out our blog | Subscribe to our reports.

 

Topics: Threat Bulletin, cyber espionage, cloud-native malware, Cavern framework, HOLLOWGRAPH, Microsoft Graph API malware, DNS tunneling, Microsoft 365 calendar malware

The Hivemind

Written by The Hivemind

Subscribe to Email Updates

Lists by Topic

see all

Posts by Topic

See all

Recent Posts