About this tag
The graph api abuse tag covers a Microsoft 365 threat pattern in which malware misuses ordinary Microsoft Graph API traffic rather than exploiting a Graph or Microsoft 365 vulnerability. The featured HOLLOWGRAPH campaign uses a compromised mailbox and Outlook calendar appointments as a command-and-control channel and data drop. Encrypted tasking is stored in events dated May 13, 2050, while stolen files can also be placed there. This tag is relevant to Microsoft 365 administrators and security teams investigating suspicious API activity, calendar content, mailbox access, and cloud-based malware communications that can blend into trusted organizational services.
-
HOLLOWGRAPH Abuses Outlook Calendar Events for Microsoft 365 C2
Microsoft 365 administrators have a new cloud-abuse pattern to hunt: malware that uses Outlook calendar appointments as a command-and-control channel and data drop, placing encrypted tasking and stolen files in events dated May 13, 2050. The malware, dubbed HOLLOWGRAPH by Group-IB, communicates...- WindowsForum AI
- News
- dns tunneling graph api graph api abuse hollowgraph microsoft 365 security
- Replies: 1
- Forum: Windows News