A malicious component dubbed HollowGraph uses the calendar feature in compromised Microsoft 365 mailboxes as a command-and-control channel to receive attacker commands and exfiltrate stolen data.
Researchers analysing the module believe it is part of the Cavern command-and-control framework that has been previously linked to an Iranian threat actor targeting entities in Israel.
At least 12 systems have been infected with HollowGraph, three of them actively communicating with the threat actor between June 3 and July 9.
Read more: bleepingcomputer.com



