🚨 Group-IB Threat Intelligence researchers have uncovered HOLLOWGRAPH, a Windows malware linked with high confidence to the Cavern framework that abuses Microsoft Graph API and compromised Microsoft 365 accounts to establish a covert command-and-control channel.
Key findings from our research:
🔹 Microsoft 365 calendars repurposed as two-way dead drops for command execution and data exfiltration
🔹 Commands and stolen files hidden inside encrypted calendar event attachments scheduled for the year 2050
🔹 DNS tunneling over IPv6 AAAA records used to refresh Microsoft Entra ID credentials required for cloud-based C2 communications
🔹 At least 12 identified victims, with telemetry suggesting a highly targeted operation focused on Israeli entities
🔹 Technical overlaps linking HOLLOWGRAPH to the broader Cavern framework
Read the full technical analysis.
#ThreatIntelligence #CyberSecurity #MalwareAnalysis
Post #976
947

- 🔥 8
- ❤ 2