Introduction to Malware Binary Triage (IMBT) Course
Looking to level up your skills? Get 10% off using coupon code: MWNEWS10 for any flavor.
Enroll Now and Save 10%: Coupon Code MWNEWS10
Note: Affiliate link – your enrollment helps support this platform at no extra cost to you.
Key Takeaways
- HOLLOWGRAPH is a Windows espionage backdoor delivered as a .NET NativeAOT DLL masquerading as a Brotli library.
- It uses compromised Microsoft 365 calendar events as a two-way dead drop for tasking and exfiltration.
- Hybrid RSA-OAEP and AES-256-GCM encryption protects Graph payloads, with separate RSA key pairs for each direction.
- DNS tunneling over IPv6 AAAA records refreshes Entra ID credentials and preserves mailbox access after secret rotation.
- Picus Platform lets teams simulate HOLLOWGRAPH attacks and validate security controls against the malware.
HOLLOWGRAPH is a Windows espionage backdoor, delivered as a .NET NativeAOT-compiled DLL, that was first observed in early June 2026 [1].
Article Link: HOLLOWGRAPH Backdoor Turns Microsoft 365 Calendars Into a C2 Channel