top of page
ALL POSTS
Project CAV3RN Abuses Outlook Calendar Events for C2 Communication and Covert Israeli Surveillance
Key Findings Project CAV3RN, an espionage framework targeting Israeli organizations, now uses Outlook calendar events as a command-and-control channel accessed through Microsoft Graph The new AzureCommunication.dll module hides commands in calendar events dated to 2050 to avoid detection; operators use encrypted attachments for payload delivery If Microsoft Graph fails, the malware retrieves backup credentials through DNS AAAA records, using the recovery domain cloudlanecdn[.
Jul 213 min read
HollowGraph Malware Exploits Microsoft 365 Events to Conceal C2 Communications and Stolen Data
Key Findings HollowGraph malware uses hijacked Microsoft 365 calendar events dated 2050 as a command-and-control channel, disguising malicious traffic as legitimate Microsoft Graph API activity The .NET implant supports only two commands (get and send) and never connects to attacker-owned servers, instead treating a compromised mailbox calendar as a two-way dead drop Tasking and exfiltrated files are encrypted with hybrid RSA-OAEP and AES-256-GCM encryption, with separate key
Jul 204 min read
bottom of page
