View Ridge Security
Back to Cyber HoseThreat Research & Deep Dives

HollowGraph Malware Uses Microsoft 365 Calendar for Stealthy C2

🕵️ RESEARCH & DEEP DIVES

  • HollowGraph malware uses Microsoft 365 calendar for stealthy C2 communications — BleepingComputer
    HollowGraph malware abuses Microsoft 365 calendar events to receive commands and exfiltrate data, targeting organizations in Israel.

    • Targets Microsoft 365 mailboxes, focusing on organizations in Israel
    • Uses Microsoft Graph API with hardcoded credentials to access mailbox calendar
    • Commands and stolen data hidden in calendar events dated May 13, 2050
    • Employs hybrid RSA and AES-256-GCM encryption for secure C2 communication
    • Uses DNS tunneling via IPv6 AAAA queries to update Microsoft Entra ID credentials
  • Authenticated RCE in EGroupware via Malicious eTemplate Upload (CVE-2026-40187) — CVE ThreatInt
    Authenticated administrators can execute OS commands on EGroupware servers by uploading malicious eTemplate XML files.

    • Applies to EGroupware versions 26.0 and earlier
    • Vulnerability allows OS-level Remote Code Execution (RCE)
    • Exploited by uploading a malicious eTemplate XML file (.xet) to the /etemplates VFS mount
    • Attack leverages PHP eval() call with unescaped backtick characters to execute shell commands
    • Requires authenticated administrator privileges to exploit
  • Exposed Server Reveals AI-Assisted Phishing Toolkit Targeting Windows via WebDAV — The Hacker News
    An AI-assisted phishing toolkit delivers infostealers via WebDAV shares to Windows users, primarily in Mexico.

    • Targets Windows users, primarily in Mexico, via fake government ID lookup sites
    • Delivers infostealer malware through WebDAV shares using .scr executables disguised as PDFs
    • Exploits WebDAV working-directory hijack vulnerability (CVE-2025-33053) and tests 59 signed binaries for hijack
    • Operator used generative AI tools to develop, test, and document phishing delivery methods
    • Campaign logged 77,098 requests over 5.5 days with 96.9% launch activity from Mexico
  • Attackers Use 'TFF Trap' Fileless Loader to Deploy RATs in BEC Phishing Campaigns — Dark Reading
    Attackers use fileless loaders in business email compromise phishing campaigns to deploy multiple remote access trojans and stealers.

    • Targets include victims of business email compromise (BEC) phishing campaigns
    • Delivers remote access trojans (RATs) and stealers like Agent Tesla, Remcos, XWorm, Best Private Logger
    • Uses fileless techniques and loaders with low detection rates to evade security tools

🔓 CVEs & KEV

  • 19 CVEs reported with the worst scoring 8.0 — Various sources

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check