entra id (1)

31205217676?profile=RESIZE_400xA novel espionage implant, called HollowGraph, is hijacking Microsoft 365 calendars to establish a covert command and control (C2) channel.  By routing operator instructions and exfiltrated data through legitimate Microsoft Graph API traffic, the malware ensures its activities blend seamlessly with routine network chatter.[1]

The .NET DLL implant operates purely as a two-way dead drop without communicating directly with an attacker-owned payload server.  To receive tasking, HollowGraph queries t