Skip to main content

Four Incidents, One Pattern: Trusted Platforms Are the New Perimeter

STATUS: Ongoing SEVERITY: 8/10 AUDIENCE: Government, Defense, Critical Infrastructure Security Leads

Jul 29, 2026

·

Blog

·

Secure Communications

A single week of reporting ties together espionage tooling that hides inside Microsoft 365, a cascading supply-chain compromise of collaboration software, hijacked edge devices used for military surveillance, and ten months of undetected access to a foreign ministry's personnel data.

What Happened

Four separate disclosures, the same underlying failure mode. Group-IB identified HOLLOWGRAPH, a Windows implant that turns a compromised Microsoft 365 mailbox's calendar into a covert command-and-control channel, moving tasking and stolen files through ordinary Microsoft Graph API traffic1. There is no vulnerability to patch — the malware abuses trust and permissions that organizations already grant.

Separately, South Korean researchers at ENKI WhiteHat documented Kimsuky (APT43) compromising two collaborative-work software vendors — one through an exploited mail-server flaw, one through employee social engineering — then using stolen vendor infrastructure data to breach the vendors' own downstream customers2. Tampered login pages and absent multifactor authentication both contributed to the cascade.

Dutch intelligence services AIVD and MIVD disclosed that a Russian intelligence service has been systematically hijacking internet-connected IP cameras across NATO states and Ukraine, using AI-assisted image analysis to track weapons shipments and military logistics — and, in Ukraine, to help target strikes on personnel and equipment3. None of the documented access required a zero-day; default credentials and exposed management interfaces were sufficient.

And South Korea's Ministry of Foreign Affairs disclosed that the Korea National Diplomatic Academy's online training platform was compromised for nearly ten months before detection, exposing personal data on at least 6,000 current and former diplomatic personnel, including roughly 350 attachés currently stationed abroad4. The breach was found by an outside agency, not the ministry itself.

What Attackers Gained – and What They Can Do with It

Attacker Gain
What It Enables
Operational Consequence
Post-Compromise Risk
Legitimate M365 API access via a compromised mailbox
Route command-and-control traffic through ordinary, already-permitted Microsoft Graph API calls.
C2 traffic is indistinguishable from normal business activity to conventional network monitoring.
Removing the malware doesn't revoke the underlying account and app permissions that enabled the abuse in the first place.
Stolen vendor infrastructure data
Use one compromised groupware vendor's data to breach that vendor's own downstream customers.
A single vendor compromise cascades into every organization that trusted that vendor.
Each downstream customer must independently verify their own exposure, since the vendor breach doesn't map directly to any one victim.
Live video feeds of military logistics
Track weapons shipments, troop movements, and transport routes in near real time.
Adversary gains a persistent surveillance capability with no need for further intrusion.
Feed access can inform strike targeting even after the initial compromise is remediated elsewhere.
Personal data on diplomatic personnel
Build a profile of current and former diplomatic staff and their postings.
Enables targeted follow-on operations — recruitment, coercion, or further phishing — against named individuals.
Exposed personnel remain a target for the remainder of their careers, regardless of when the breach is remediated.

Why This Matters

Old Assumption
Current Reality
BlackBerry Response
Perimeter defense and vulnerability patching are the primary defense
Three of four incidents this cycle involved no exploited vulnerability at all — just abused trust, weak credentials, or missing MFA
Comms and endpoint architecture built to operate outside shared, general-purpose trust boundaries, not dependent on patch cadence alone
A single vendor compromise is contained to that vendor
Kimsuky used one groupware vendor's stolen infrastructure data to cascade into every downstream customer
Certified, narrow-scope platform with no shared multi-tenant vendor dependency to cascade through
Detection happens close to the time of compromise
The Korea Diplomatic Academy breach ran undetected for nearly ten months before an outside agency flagged it
Continuous compliance monitoring designed to surface anomalous access rather than rely on periodic audit

IMMEDIATE 
Audit OAuth/Entra application permissions and Microsoft Graph API activity across your Microsoft 365 tenant for anomalous calendar or mailbox operations.
IMMEDIATE 
Inventory collaboration and groupware vendors with standing access to your infrastructure, and confirm MFA is enforced on every vendor-facing login.
SHORT-TERM 
Identify any internet-exposed cameras or IoT devices on organizational networks still running default credentials or open management interfaces.
SHORT-TERM 
Extend UEM compliance monitoring beyond core endpoints to training, administrative, and other lower-priority systems that hold sensitive personnel data.
ONGOING
Build detection-timeline assumptions into resilience planning — treat "undetected for months" as the expected case for trusted-platform abuse, not the exception.

BlackBerry Secure Communications Position

When four unrelated campaigns all bypass code entirely and exploit trust instead, the lesson isn't about any one platform. It's that shared, multi-tenant trust boundaries are now the primary attack surface, and the only durable defense is operating outside them.

Citations:

1. HOLLOWGRAPH: Turning Microsoft 365 Calendars into Covert Command-and-Control Channels (Group-IB, July 20, 2026).

2. Analysis of Kimsuky's Attack on a South Korean Groupware Vendor Using a New Gomir Family Variant (ENKI WhiteHat, July 20, 2026).

3. Cybersecurity Advisory: Russian State Actors are Compromising IP Cameras in Europe for Military Purposes (General Intelligence and Security Service (AIVD) and Military Intelligence and Security Service (MIVD), July 10, 2026).

4. Personal Data of 10,000 Diplomats Leaked in Suspected Cyberattack (The Korea Times, July 21, 2026).

Get updates about the latest in-depth knowledge for secure communications.

The New Standard

Watch the Webinar: The Case for Mission-Critical Communications

Join us for a 45-minute webinar where our experts explore the technical and operational framework to ensure mission-certified secure communications across encryption, architecture, sovereign control, independent validation, and mission orchestration.

Watch now