Stay ahead with Daily CyberSecurity. We deliver rapid zero-hour alerts and expert analysis on critical vulnerabilities, CVEs, and emerging cyber threats.
Microsoft 365 für Schule & Beruf | Lehren, lernen, arbeiten mit Windows, Office, Copilot & Co. | Malter365.de ist ein unabhängiges Angebot von Stefan Malter.
Stay ahead with Daily CyberSecurity. We deliver rapid zero-hour alerts and expert analysis on critical vulnerabilities, CVEs, and emerging cyber threats.
Mastodon account of the most reliable cybersecurity news platforms bringing exclusive dark web, tech, and hacking news. Contact: admin@hackread.com.
Practical #privacy and simple #cybersecurity for everyone. Articles posted =/= endorsement/agreement. This account no longer monitored. Please contact us via other channels: https://thenewoil.org/en/links/#contact
Hier geht es um Cybersecurity – aktuell, kompakt und fachlich. # Sicherheitslücken & #Cyberangriffe #KI & #Security #Ransomware, #Phishing & #Threats Identity, Access & #Netzwerksicherheit Fachartikel & Video-Podcasts Wir teilen aktuelle Entwicklungen und relevantes Security-Wissen für alle, die IT-Sicherheit im Blick behalten müssen. Gebt uns Feedback! Schreibt, kommentiert, widersprecht! Eure Sicht interessiert uns.
OffSeq is a cybersecurity company enhancing organizational digital resilience through comprehensive protection against evolving cyber threats. We offer specialized services for businesses of all sizes, with particular expertise in Baltic, Scandinavian, Belgian markets and EU regulatory compliance.
News rund um Technik, IT und Digitales. Offizieller Account 🤖 Die meisten Posts sind automatisiert, aber alle searchable http://heise.de/impressum.html & http://heise.de/privacy
Stay ahead with Daily CyberSecurity. We deliver rapid zero-hour alerts and expert analysis on critical vulnerabilities, CVEs, and emerging cyber threats.
🎯 Threat Intelligence
Group-IB Threat Intelligence has identified HOLLOWGRAPH, a .NET NativeAOT-compiled DLL malware attributed with high confidence to the Cavern backdoor framework. The malware transforms Microsoft 365 calendars into covert command-and-control channels using the Microsoft Graph API, communicating through a compromised Israeli mailbox.
🔹 Technical Overview
HOLLOWGRAPH operates with only two commands: get and send. Both execute exclusively through trusted Microsoft cloud infrastructure. The malware never reaches out directly to attacker-owned servers. Instead, it uses the Microsoft Graph API to treat a compromised mailbox's calendar as a two-way dead-drop.
🔹 C2 Mechanism
The calendar-based C2 works as follows:
- Tasking: Operators plant calendar events containing encrypted commands as attachments.
- Exfiltration: The implant creates its own calendar events with encrypted stolen data attached as files.
- Concealment: Every event is dated to 13 May 2050, ensuring the mailbox owner is unlikely to notice them.
All Graph payloads use hybrid RSA + AES encryption. Two separate key pairs keep tasking and exfiltration channels cryptographically independent.
🔹 Credential Renewal Channel
HOLLOWGRAPH maintains a secondary communication channel through DNS tunneling. It performs IPv6 AAAA record queries against the attacker-controlled domain cloudlanecdn[.]com to refresh its Microsoft Entra ID (Azure AD) credentials. Updated values are written to an on-disk configuration file named logAzure.txt.
This dual-channel architecture provides resilience. Even if the primary Graph API channel is disrupted, the malware can continue receiving refreshed authentication tokens through DNS.
🔹 Victimology
Group-IB identified 12 systems carrying the implant. Only approximately three were actively communicating with attacker infrastructure. The recovered indicators, an Israeli mailbox used for exfiltration and malware samples uploaded from Israel, suggest focused interest in Israeli entities rather than broad opportunistic compromise.
🔹 Detection Considerations
Defenders monitoring Microsoft 365 environments should look for: • Calendar events with future dates far beyond typical scheduling horizons (e.g., 2050) • Unusual file attachments on calendar entries • DNS queries to cloudlanecdn[.]com with AAAA record types • The on-disk artifact logAzure.txt • Authentication patterns from .NET NativeAOT binaries interacting with Microsoft Graph API
🔹 Attribution
Group-IB links HOLLOWGRAPH to the Cavern backdoor framework with high confidence, based on code and behavioral similarities with known Cavern components.
🔹 HOLLOWGRAPH #ThreatIntelligence #C2 #Microsoft365 #MalwareAnalysis
🔗 Source: https://www.group-ib.com/blog/hollowgraph-microsoft-365/
Writer for Practical365.com. Lead author of the Office 365 for IT Pros eBook. Microsoft MVP.
Stay ahead with Daily CyberSecurity. We deliver rapid zero-hour alerts and expert analysis on critical vulnerabilities, CVEs, and emerging cyber threats.
Stay ahead with Daily CyberSecurity. We deliver rapid zero-hour alerts and expert analysis on critical vulnerabilities, CVEs, and emerging cyber threats.
Stay ahead with Daily CyberSecurity. We deliver rapid zero-hour alerts and expert analysis on critical vulnerabilities, CVEs, and emerging cyber threats.
Microsoft 365 für Schule & Beruf | Lehren, lernen, arbeiten mit Windows, Office, Copilot & Co. | Malter365.de ist ein unabhängiges Angebot von Stefan Malter.
Aktivistin für Digitale Unabhängigkeit, Trans* und LGBTIQ+ Rechte, Linux Server und Netzwerk Administratorin seit 25 Jahren, Infrastructure Engineer, Webdeveloper, Kaffeejunkie, Mutter > Eigentümerin der #Mastodon Instanz lsbt.me > Eigentümerin der App #FediSuite > Eigentümerin des #APBoard > Nur noch #Linux seit 1998! > Mitglied bei DIE LINKE ⓘ 𝘈𝘵𝘵𝘦𝘯𝘵𝘪𝘰𝘯: 𝘛𝘩𝘪𝘴 𝘶𝘴𝘦𝘳 𝘪𝘴 𝘴𝘶𝘴𝘱𝘦𝘤𝘵𝘦𝘥 𝘰𝘧 𝘣𝘦𝘪𝘯𝘨 𝘱𝘢𝘳𝘵 𝘰𝘧 𝘢 𝘵𝘦𝘳𝘳𝘰𝘳𝘪𝘴𝘵 𝘰𝘳𝘨𝘢𝘯𝘪𝘻𝘢𝘵𝘪𝘰𝘯 𝘤𝘢𝘭𝘭𝘦𝘥 𝘈𝘯𝘵𝘪𝘧𝘢 𝘎𝘮𝘣𝘏 & 𝘊𝘰.𝘒𝘎. 𝘐𝘯𝘤. 𝘗𝘭𝘦𝘢𝘴𝘦 𝘳𝘦𝘱𝘰𝘳𝘵 𝘢𝘯𝘺 𝘴𝘶𝘴𝘱𝘪𝘤𝘪𝘰𝘶𝘴 𝘣𝘦𝘩𝘢𝘷𝘪𝘰𝘳. ⓘ #aktivist #antifa #fckafd #afdverbotjetzt #fcknzs #fckcdu #fckmrz #fckcsu #politician #feminist #lgbt 🏳️🌈 #queer #trans 🏳️⚧️ #transgender #tutor #teacher #writer #author #sexworker #she #her #fedi22
HCC is een vereniging voor iedereen die geïnteresseerd is in computers, technologie en alles wat daarbij komt kijken. Sinds onze oprichting in 1977 hebben we talloze leden verwelkomd en een gemeenschap opgebouwd die draait om kennisdeling, persoonlijke groei en het vieren van de liefde voor technologie. Onze vereniging biedt een scala aan activiteiten en mogelijkheden, voor beginners, gevorderden als mensen die het moeilijk vinden om de snelle ontwikkelingen op digitaal gebied bij te blijven.
🤖 Bot de veille cyber/IA — curation automatique: CVE critiques, exploits 0-day, data breaches, reverse engineering, attaques GNSS (jamming/spoofing), crypto post-quantum. FR/EN. Maintenu par un dev anonyme.
Decoding #ransomware groups since before Bitcoin existed. Deep threat intel for defenders who actually read the tech writeups. 🔗 ransomNews.online 💼 linkedin.com/company/ransom... 🌉 bridged from 🦋 ransomnews.online, follow @bsky.brid.gy to interact
The Original #PowerPlatform Advisor. Former 11x Microsoft MVP. Low-code 4 life.