HOLLOWGRAPH: Turning Microsoft 365 Calendars into Covert Command-and-Control Channels
HOLLOWGRAPH is a sophisticated espionage malware campaign that abuses the Microsoft Graph API to convert compromised Microsoft 365 calendars into covert command-and-control channels. The malware creates calendar events dated to 2050 with encrypted attachments to exfiltrate data and receive commands. It also uses a secondary DNS tunneling channel via IPv6 AAAA records to refresh Microsoft Entra ID credentials for authentication. Communications are secured with hybrid RSA and AES-256-GCM encryption using separate key pairs for inbound and outbound traffic. Twelve infected systems have been identified, mainly targeting Israeli entities, with three actively communicating with attackers. The operation is attributed to the LYCEUM adversary and demonstrates high technical sophistication and focused espionage since at least June 2026.
AI Analysis
Technical Summary
This malware campaign leverages Microsoft Graph API abuse to transform Microsoft 365 calendars into covert C2 infrastructure by creating future-dated calendar events containing encrypted attachments for data exfiltration and command reception. It employs a secondary DNS tunneling channel using IPv6 AAAA records to refresh authentication credentials (Microsoft Entra ID). Communications are protected by hybrid RSA and AES-256-GCM encryption with distinct key pairs for inbound and outbound channels. The campaign targets primarily Israeli entities, with twelve infected hosts identified and three actively communicating. The adversary LYCEUM is suspected, indicating a well-resourced espionage operation with disciplined targeting and advanced technical methods.
Potential Impact
The malware enables attackers to covertly exfiltrate sensitive data and issue commands through Microsoft 365 calendar events, bypassing traditional network monitoring. The use of encrypted attachments and DNS tunneling for credential refresh enhances stealth and persistence. This compromises confidentiality and potentially integrity of targeted systems. The focused targeting of Israeli entities suggests espionage motives. No widespread exploitation or known public exploits have been reported.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Organizations should monitor for suspicious calendar events, especially those dated far in the future with encrypted attachments, and investigate unusual DNS AAAA record queries. Review and restrict Microsoft Graph API permissions to the minimum necessary. Employ anomaly detection for calendar and DNS activity. Follow updates from Microsoft and security vendors for official fixes or mitigations.
Affected Countries
Israel
Indicators of Compromise
- hash: 315bdba98c6fe863d39f6afccc727e17d5aea63bf21259444fa988cae56d61c1
- domain: cloudlanecdn.com
- hash: 1573e125197ec77d8e9930c611ba2802ee59e19629396b5e99b426b46c53bd25
- hash: 75e51774b8f79e5f256eaae639635f911b3e744d4774fd6068dd980255621509
- hash: b3d0f6e4e3be395fd7cf9e8101c89963d77216578cbb117a6ac9bc3564485eff
- hash: f3f3006f8304788251b153d53b305322b8acab0c66ec816b8d9f101bcc851da3
- domain: p.cloudlanecdn.com
- domain: q.cloudlanecdn.com
HOLLOWGRAPH: Turning Microsoft 365 Calendars into Covert Command-and-Control Channels
Description
HOLLOWGRAPH is a sophisticated espionage malware campaign that abuses the Microsoft Graph API to convert compromised Microsoft 365 calendars into covert command-and-control channels. The malware creates calendar events dated to 2050 with encrypted attachments to exfiltrate data and receive commands. It also uses a secondary DNS tunneling channel via IPv6 AAAA records to refresh Microsoft Entra ID credentials for authentication. Communications are secured with hybrid RSA and AES-256-GCM encryption using separate key pairs for inbound and outbound traffic. Twelve infected systems have been identified, mainly targeting Israeli entities, with three actively communicating with attackers. The operation is attributed to the LYCEUM adversary and demonstrates high technical sophistication and focused espionage since at least June 2026.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This malware campaign leverages Microsoft Graph API abuse to transform Microsoft 365 calendars into covert C2 infrastructure by creating future-dated calendar events containing encrypted attachments for data exfiltration and command reception. It employs a secondary DNS tunneling channel using IPv6 AAAA records to refresh authentication credentials (Microsoft Entra ID). Communications are protected by hybrid RSA and AES-256-GCM encryption with distinct key pairs for inbound and outbound channels. The campaign targets primarily Israeli entities, with twelve infected hosts identified and three actively communicating. The adversary LYCEUM is suspected, indicating a well-resourced espionage operation with disciplined targeting and advanced technical methods.
Potential Impact
The malware enables attackers to covertly exfiltrate sensitive data and issue commands through Microsoft 365 calendar events, bypassing traditional network monitoring. The use of encrypted attachments and DNS tunneling for credential refresh enhances stealth and persistence. This compromises confidentiality and potentially integrity of targeted systems. The focused targeting of Israeli entities suggests espionage motives. No widespread exploitation or known public exploits have been reported.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Organizations should monitor for suspicious calendar events, especially those dated far in the future with encrypted attachments, and investigate unusual DNS AAAA record queries. Review and restrict Microsoft Graph API permissions to the minimum necessary. Employ anomaly detection for calendar and DNS activity. Follow updates from Microsoft and security vendors for official fixes or mitigations.
Affected Countries
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.group-ib.com/blog/hollowgraph-microsoft-365/"]
- Adversary
- LYCEUM
- Pulse Id
- 6a5e7a9d5abc92aab562f131
- Threat Score
- null
Indicators of Compromise
Hash
| Value | Description | Copy |
|---|---|---|
hash315bdba98c6fe863d39f6afccc727e17d5aea63bf21259444fa988cae56d61c1 | — | |
hash1573e125197ec77d8e9930c611ba2802ee59e19629396b5e99b426b46c53bd25 | — | |
hash75e51774b8f79e5f256eaae639635f911b3e744d4774fd6068dd980255621509 | — | |
hashb3d0f6e4e3be395fd7cf9e8101c89963d77216578cbb117a6ac9bc3564485eff | — | |
hashf3f3006f8304788251b153d53b305322b8acab0c66ec816b8d9f101bcc851da3 | — |
Domain
| Value | Description | Copy |
|---|---|---|
domaincloudlanecdn.com | — | |
domainp.cloudlanecdn.com | — | |
domainq.cloudlanecdn.com | — |
Threat ID: 6a5f49772a4a8d5989f62c3c
Added to database: 07/21/2026, 10:27:03 UTC
Last enriched: 07/21/2026, 10:46:34 UTC
Last updated: 07/21/2026, 14:55:47 UTC
Views: 32
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.