Threat Intelligence Brief
Curated summary with source attribution
Source: thehackernews.com
Threat Risk: High
Victim: Israeli organization
Incident: Deployment of the HollowGraph espionage implant for stealthy data exfiltration via M365.
Impact: Unauthorized access to sensitive data and long-term espionage via a trusted cloud service.
Attacker: Likely Iranian-linked actors (associated with Cavern/MuddyWater/Lyceum)
Analysis: HollowGraph employs a highly stealthy C2 mechanism by utilizing legitimate Microsoft 365 calendar events as a two-way communication channel. By placing instructions and stolen files in events dated far into the future, the malware bypasses traditional network controls and blends in with normal cloud traffic. The operation also uses DNS queries to refresh Entra ID credentials, ensuring persistent access to the compromised mailbox.
Recommendations: Audit Microsoft 365 calendar events for anomalies, specifically entries dated far into the future.; Monitor for unusual DNS traffic patterns associated with Entra ID credential updates.; Implement strict API permission controls for Microsoft Graph to limit the impact of compromised mailboxes.
Source: The Hacker News / Group-IB
Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source