HOLLOWGRAPH Backdoor Turns Microsoft 365 Calendars Into a C2 Channel

Introduction to Malware Binary Triage (IMBT) Course

Looking to level up your skills? Get 10% off using coupon code: MWNEWS10 for any flavor.

Enroll Now and Save 10%: Coupon Code MWNEWS10

Note: Affiliate link – your enrollment helps support this platform at no extra cost to you.

HOLLOWGRAPH Backdoor Turns Microsoft 365 Calendars Into a C2 Channel

Key Takeaways

  • HOLLOWGRAPH is a Windows espionage backdoor delivered as a .NET NativeAOT DLL masquerading as a Brotli library.
  • It uses compromised Microsoft 365 calendar events as a two-way dead drop for tasking and exfiltration.
  • Hybrid RSA-OAEP and AES-256-GCM encryption protects Graph payloads, with separate RSA key pairs for each direction.
  • DNS tunneling over IPv6 AAAA records refreshes Entra ID credentials and preserves mailbox access after secret rotation.
  • Picus Platform lets teams simulate HOLLOWGRAPH attacks and validate security controls against the malware.

HOLLOWGRAPH is a Windows espionage backdoor, delivered as a .NET NativeAOT-compiled DLL, that was first observed in early June 2026 [1].

Article Link: HOLLOWGRAPH Backdoor Turns Microsoft 365 Calendars Into a C2 Channel