Threat Intelligence Brief
Curated summary with source attribution
Source: securityweek.com
Threat Risk: High
Victim: Israeli organizations
Incident: Deployment of HollowGraph malware for C&C and data exfiltration via Microsoft 365.
Impact: Stealthy data exfiltration and long-term persistence through legitimate SaaS traffic.
Attacker: Lyceum (Iran-nexus)
Analysis: The HollowGraph malware leverages the Microsoft 365 Graph API to establish a stealthy C&C channel, treating calendar events as dead-drops for commands and data exfiltration. By dating events far into the future, the malware avoids alerting the mailbox owner while maintaining persistent communication. It further secures its operation using hybrid RSA and AES encryption alongside a backup DNS tunneling channel.
Recommendations: Monitor for unusual Graph API activity and the creation of calendar events dated far in the future.; Audit Microsoft Entra ID logs for suspicious application registrations or unexpected token usage.; Implement strict conditional access policies to limit API access to trusted devices and authenticated locations.
Source: SecurityWeek
Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source