Affected Systems

Microsoft 365 environments with compromised mailboxes. Threat actors leverage Microsoft Graph API and calendar features to establish covert command-and-control channels. No specific product vulnerability; relies on compromised credentials or initial access.

Exploitation Status

Active campaign observed. Attackers are using this technique in the wild to abuse legitimate Microsoft 365 functionality for C2 communication and data exfiltration. No CVE assigned as this is abuse of intended functionality rather than a vulnerability.

Business Impact

Organizations using Microsoft 365 face detection challenges as HollowGraph blends malicious traffic with legitimate Graph API and calendar activity. Traditional network monitoring may miss this C2 channel since it uses authorized Microsoft services. Compromised mailboxes can serve as persistent, stealthy exfiltration points. Incident response teams must review calendar event logs and Graph API activity, which are not typically monitored for malicious behavior.

Urgency

🟠 Within 24 hours

Recommended Actions

  • Enable and review Microsoft 365 Unified Audit Logs, specifically calendar event creation/modification and Graph API access patterns for anomalies
  • Implement conditional access policies to restrict Graph API access and enforce MFA for all Microsoft 365 accounts
  • Monitor for unusual calendar event patterns: high-frequency creation/deletion, events with encoded data in fields, or calendar access from unexpected IP ranges
  • Review mailbox audit logs for compromised accounts and reset credentials for any accounts showing suspicious calendar or Graph API activity
  • Deploy Microsoft Defender for Office 365 or equivalent CASB solution to detect anomalous Graph API usage and calendar-based data exfiltration patterns