Post #3983813
2026-07-21 10:49 UTC
HollowGraph runs its entire C2 over Microsoft Graph: calendar events dated to the year 2050, used as a dead-drop. All the malicious traffic looks like normal Microsoft 365.
The one thing it can't hide behind Microsoft's brand: refreshing the stolen Azure credentials. That goes out over DNS to cloudlanecdn[.]com, a domain dressed up as a CDN.
Solid write-up from Group-IB:
https://www.group-ib.com/blog/hollowgraph-microsoft-365/
#threatintel #blueteam #infosec
Replies (0)
No replies.