TGViewer
Group-IB Group-IB @group_ib · 2.52K subscribers
Post #976 947
🚨 Group-IB Threat Intelligence researchers have uncovered HOLLOWGRAPH, a Windows malware linked with high confidence to the Cavern framework that abuses Microsoft Graph API and compromised Microsoft 365 accounts to establish a covert command-and-control channel.

Key findings from our research:
🔹 Microsoft 365 calendars repurposed as two-way dead drops for command execution and data exfiltration
🔹 Commands and stolen files hidden inside encrypted calendar event attachments scheduled for the year 2050
🔹 DNS tunneling over IPv6 AAAA records used to refresh Microsoft Entra ID credentials required for cloud-based C2 communications
🔹 At least 12 identified victims, with telemetry suggesting a highly targeted operation focused on Israeli entities
🔹 Technical overlaps linking HOLLOWGRAPH to the broader Cavern framework

Read the full technical analysis.

#ThreatIntelligence #CyberSecurity #MalwareAnalysis
  • 🔥 8
  • ❤ 2
More from @group_ib
  1. Sep 23, 2026🚨Group-IB researchers have uncovered RemControl, a previously undocumented Android bankin…
  2. Sep 17, 2026🚨Group-IB Threat Intelligence has uncovered 29 new samples linked to the HEAVYGRAM and CR…
  3. Sep 14, 2026🚨 Inside the Smishing Triad’s Phishing Cockpit Group-IB’s latest research dives into JWR,…
  4. Sep 9, 2026🚨 Group-IB uncovers Vwork, a weaponized fork of the open-source Android app cloner Shelte…
  5. Sep 3, 2026🚨 Outsider Phishing Kit: a resilient PhaaS threat Group-IB researchers uncovered the Outs…
  6. Sep 1, 2026🚨 Cybercrime is evolving, and so is the underground economy behind it. Group-IB has uncov…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →