IIA A.I CyberSecurity Scoring
IIA
Company Information
Website:http://www.Innovationisrael.org.il
Employees number:201
Number of followers:113,366
NAICS:5417
Industry Type:Research Services
Homepage:Innovationisrael.org.il
IIA Risk Score (AI oriented)
Between 700 and 749
IIAResearch Services
Updated:
20/07/2026
20/07/2026
738/1000
Moderate
Ba
IIA Global Score (TPRM)
xxxx
IIAResearch Services
Score locked

IIAModerate
Current Score
738Ba (MODERATE)
01000
1 incidents
-17 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JULY 2026
738
JUNE 2026
754
Cyber Attack
03 Jun 2026 • IIA
Microsoft and Israeli organization: HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050
HollowGraph: Espionage Malware Hijacks Microsoft 365 Calendars for Stealthy C2 Operations
737
HIGH-17
MICISR1784565175
HollowGraph: Espionage Malware Hijacks Microsoft 365 Calendars for Stealthy C2 Operations
Security researchers at Group-IB have uncovered a novel espionage implant, HollowGraph, which leverages a compromised Microsoft 365 calendar as a command-and-control (C2) channel. The malware, a .NET DLL, evades detection by embedding operator instructions and exfiltrating stolen data via calendar events dated to 2050, ensuring they remain hidden from typical user activity.
### How HollowGraph Operates
HollowGraph exploits the Microsoft Graph API to blend malicious traffic with legitimate Microsoft 365 communications. Instead of connecting to an attacker-controlled server, it uses the victim’s mailbox calendar as a dead drop:
- Tasking retrieval: Queries a pre-planted event (dated 2050-05-13) to extract instructions from an attached file.
- Data exfiltration: Encrypts stolen files, creates a new far-future event, and uploads the data as attachments.
- Encryption: Uses hybrid RSA and AES-256, with separate key pairs for incoming and outgoing traffic.
A secondary channel maintains persistence via DNS queries to the attacker domain cloudlanecdn[.]com, refreshing Entra ID (Azure AD) credentials (tenant ID, client ID, client secret) stored in a disguised log file (logAzure.txt).
### Attribution & Campaign Scope
Group-IB links HollowGraph to Cavern, a modular backdoor framework recently documented by Check Point and attributed to Cavern Manticore, an Iranian threat actor with ties to MuddyWater and Lyceum. However, Group-IB stops short of definitive attribution, citing only a low-confidence overlap with Lyceum (an OilRig subgroup).
The campaign targeted at least 12 machines, with active communication observed between June 3 and July 9, 2026. Victims included an Israeli organization, though Group-IB treats this as geographic targeting rather than a definitive link to the attacker. The limited footprint suggests targeted espionage, though the technique could be repurposed for broader attacks.
### Detection & Defense Challenges
HollowGraph exploits legitimate Microsoft 365 functionality, requiring no software vulnerabilities only a compromised account and Graph API access. Key detection indicators include:
- Calendar anomalies: Events with 2050-05-13 dates, GUID-based subjects (e.g., Event ID:, Boss{..}ID{..}), or attachments named File{n}.txt.
- Identity risks: Unusual OAuth app permissions, newly created client secrets, or anomalous Entra ID token activity.
- DNS red flags: Frequent AAAA queries to cloudlanecdn[.]com or high-entropy subdomains.
### Broader Implications
This attack underscores the growing trend of abusing trusted cloud services for C2 operations. While previous campaigns have exploited Outlook drafts and OneDrive, HollowGraph’s use of far-future calendar events demonstrates a new evasion tactic. With victim traffic active as recently as July 2026, defenders are advised to scrutinize unusual calendar activity even in the distant future.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
MAY 2026
754
APRIL 2026
754
MARCH 2026
754
FEBRUARY 2026
754
JANUARY 2026
754
DECEMBER 2025
754
NOVEMBER 2025
754
OCTOBER 2025
754
SEPTEMBER 2025
754
AUGUST 2025
754
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for IIA ??
What was IIA's A.I Rankiteo Cyber Score in June 2026 ??
What was IIA's A.I Rankiteo Cyber Score in May 2026 ??
What was IIA's A.I Rankiteo Cyber Score in April 2026 ??
What was IIA's A.I Rankiteo Cyber Score in March 2026 ??
What was IIA's A.I Rankiteo Cyber Score in February 2026 ??
What was IIA's A.I Rankiteo Cyber Score in January 2026 ??
What was IIA's A.I Rankiteo Cyber Score in December 2025 ??
What was IIA's A.I Rankiteo Cyber Score in November 2025 ??
What was IIA's A.I Rankiteo Cyber Score in October 2025 ??
What was IIA's A.I Rankiteo Cyber Score in September 2025 ??
What was IIA's A.I Rankiteo Cyber Score in August 2025 ??
What is the average per-incident point impact on IIA's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with IIA ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view IIA's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?