A malicious component dubbed HollowGraph uses the calendar feature in compromised Microsoft 365 mailboxes as a command-and-control channel to receive attacker commands and exfiltrate stolen data.
Researchers analysing the module believe it is part of the Cavern command-and-control framework that has been previously linked to an Iranian threat actor targeting entities in Israel.
At least 12 systems have been infected with HollowGraph, three of them actively communicating with the threat actor between June 3 and July 9.
The collected indicators suggest that the threat actor is focused on organizations in Israel, pointing to a targeted attack for espionage purposes.
Microsoft 365 mailbox abuse
In a report from cybersecurity company Group-IB, researchers say that HollowGraph uses hardcoded details to authenticate to the Microsoft Graph API via a compromised Microsoft 365 account.
The configuration file is stored as logAzure.txt to appear as a regular log file, and "includes the Microsoft Entra ID tenant ID, application (client) ID, client secret, target mailbox address, command-and-control (C2) domain, and two RSA keys."
The two cryptographic keys are used to encrypt files before delivery to the attacker and to decrypt incoming tasks.
To remain under the radar, the threat actor creates calendar events dated May 13, 2050, with the title in specific formats. Commands and exfiltrated data are concealed within files attached to these calendar entries.
According to Group-IB's analysis, HollowGraph supports only two commands that let it create calendar entries with stolen files in encrypted form and search for new ones with instructions from the threat actor:
... continue reading