HollowGraph Malware Leverages Microsoft Graph for Stealthy Command‑and‑Control

Researchers have identified a new malware family named HollowGraph. The malware exploits Microsoft Graph APIs to hide its command‑and‑control traffic. By using

Researchers have identified a new malware family named HollowGraph. The malware exploits Microsoft Graph APIs to hide its command‑and‑control traffic. By using legitimate Graph requests, it evades typical network detection. The technique allows attackers to communicate with infected hosts stealthily. HollowGraph can download additional payloads through the same channel. Microsoft has not yet disclosed a patch for the abuse of Graph services. Security teams are advised to monitor unusual Graph activity. The discovery highlights the need for tighter controls on cloud APIs.