#HOLLOWGRAPH
Microsoft 365 calendars become spy drop boxes in HOLLOWGRAPH campaign
Microsoft 365 calendars become spy drop boxes in HOLLOWGRAPH campaign
Malware hides commands in appointments set for 2050 and uses Redmond's own cloud to phone home
www.theregister.com
July 22, 2026 at 11:01 PM
✨ HOLLOWGRAPH: quando il calendario di Microsoft 365 diventa un canale C2 nascosto
Leggi il blog: spcnet.it/hollowgraph-...
July 25, 2026 at 11:32 AM
Microsoft 365 calendars become spy drop boxes in HOLLOWGRAPH campaign
Microsoft 365 calendars become spy drop boxes in HOLLOWGRAPH campaign
www.theregister.com
July 20, 2026 at 3:34 PM
New HollowGraph Malware Abuses Microsoft 365 Calendar for C&C Communication
New HollowGraph Malware Abuses Microsoft 365 Calendar for C&C Communication
Part of a larger toolkit, HollowGraph uses a compromised 365 account’s calendar as a two-way dead-drop.
www.securityweek.com
July 24, 2026 at 5:12 PM
Microsoft 365 calendars become spy drop boxes in HOLLOWGRAPH campaign
Microsoft 365 calendars become spy drop boxes in HOLLOWGRAPH campaign
Malware hides commands in appointments set for 2050 and uses Redmond's own cloud to phone home
www.theregister.com
July 20, 2026 at 2:59 PM
A malicious component dubbed HollowGraph uses the calendar feature in compromised Microsoft 365 mailboxes as a command-and-control channel to receive attacker commands and exfiltrate stolen data.
New HollowGraph malware uses Microsoft Graph for stealthy C2 comms
A malicious component dubbed HollowGraph uses the calendar feature in compromised Microsoft 365 mailboxes as a command-and-control channel to receive attacker commands and exfiltrate stolen data.
www.bleepingcomputer.com
July 20, 2026 at 5:43 PM
SANS Stormcast Tuesday, July 21st, 2026: More Wordpress Details; HOLLOWGRAPH MSFT Calendar Abuse; Gitea Vulnerability
https://isc.sans.edu/podcastdetail/10016
July 21, 2026 at 2:01 AM
New HollowGraph malware uses Microsoft Graph for stealthy C2 comms
New HollowGraph malware uses Microsoft Graph for stealthy C2 comms
A malicious component dubbed HollowGraph uses the calendar feature in compromised Microsoft 365 mailboxes as a command-and-control channel to receive attacker commands and exfiltrate stolen data. [...]
www.bleepingcomputer.com
July 20, 2026 at 6:25 PM
Analysis: New HollowGraph malware uses Microsoft Graph for stealthy C2 comms
July 21, 2026 at 6:00 AM
Microsoft 365 calendars become spy drop boxes in HOLLOWGRAPH campaign
www.theregister.com/security/202...
Microsoft 365 calendars become spy drop boxes in HOLLOWGRAPH campaign
Malware hides commands in appointments set for 2050 and uses Redmond's own cloud to phone home
www.theregister.com
July 20, 2026 at 9:39 PM
Microsoft 365 calendars become spy drop boxes in HOLLOWGRAPH campaign
Microsoft 365 calendars become spy drop boxes in HOLLOWGRAPH campaign
Malware hides commands in appointments set for 2050 and uses Redmond's own cloud to phone home
www.theregister.com
July 21, 2026 at 3:00 PM
HollowGraphマルウェア、Microsoft 365カレンダーを悪用

HollowGraphの脅威が明らかに クラウドカレンダーには、日常的な予定表示以上のものが隠されている場合があります。HollowGraphマルウェアはMicrosoft 365を悪用し、密かにコマンドを受信するとともに窃取したファイルを送信します。Group-IBのサイバーセキュリティ専門家は...
HollowGraphマルウェア、Microsoft 365カレンダーを悪用
HollowGraphの脅威が明らかに クラウドカレンダーには、日常的な予定表示以上のものが隠されている場合があります。HollowGraphマルウェアはMicrosoft 365を悪用し、密かにコマンドを受信するとともに窃取したファイルを送信します。Group-IBのサイバーセキュリティ専門家は
blackhatnews.tokyo
July 22, 2026 at 2:12 PM
HollowGraph, an espionage implant, hides its command channel in a hijacked Microsoft 365 calendar over the Graph API.

No CVE, no patch. Firewalls see normal M365 traffic.

Hunt far-future calendar events with attachments in your audit logs.
HollowGraph turns Microsoft 365 into a C2 channel with no patch
HollowGraph runs its command channel through a hijacked Microsoft 365 calendar over the Graph API. No CVE, no patch: here is how to detect it.
suriq.io
July 21, 2026 at 4:08 PM
They've turned your calendar into a postbox. Commands arrive as events scheduled for the year 2099, stolen data leaves as encrypted attachments, all riding through Microsoft Graph...

https://cybersec.picussecurity.com/s/hollowgraph-backdoor-turns-microsoft-365-calendars-into-a-c2-channel-28829
August 4, 2026 at 3:00 PM
Iran's Cavern Manticore now picks its C2 channel via DNS then hides inside Google Apps Script. https://intel.threadlinqs.com/threat/TL-2026-2053 #ThreatIntel #CAV3RN #HOLLOWGRAPH #TAMECAT
August 18, 2026 at 2:42 AM
HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050

A newly discovered espionage implant has been using a hijacked Microsoft 365 calendar as its command channel, planting operator instructions and smuggling out stolen files as attachments o…
#hackernews #microsoft #news
HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050
A newly discovered espionage implant has been using a hijacked Microsoft 365 calendar as its command channel, planting operator instructions and smuggling out stolen files as attachments on calendar events dated to the year 2050. Group-IB, which named the malware HollowGraph, says the approach moves tasking and stolen data through legitimate Microsoft Graph API traffic, so the activity looks
thehackernews.com
July 21, 2026 at 1:33 PM
HOLLOWGRAPH malware turns Microsoft 365 calendars into an espionage channel

Microsoft 365 calendars have become a hiding place for espionage malware, with commands and stolen files stashed inside appointments dated to the year 2050, researchers from Group-IB discovered…
#hackernews #microsoft #news
HOLLOWGRAPH malware turns Microsoft 365 calendars into an espionage channel
Microsoft 365 calendars have become a hiding place for espionage malware, with commands and stolen files stashed inside appointments dated to the year 2050, researchers from Group-IB discovered. Targeted campaign tied to Iranian espionage activity The malware, which Group-IB calls HOLLOWGRAPH, is one component of a bigger toolkit the company links with high confidence to the Cavern backdoor framework, a modular espionage toolkit built from separate plugins that each handle a different task, previously tied …
www.helpnetsecurity.com
July 21, 2026 at 4:31 PM
Hackers Are Turning Microsoft 365 Calendar Invites Into Secret Malware Command Channels
Hackers Are Turning Microsoft 365 Calendar Invites Into Secret Malware Command Channels
A stealthy new malware strain called HOLLOWGRAPH that hijacks Microsoft 365 calendars to secretly communicate with hackers, disguising malicious commands as ordinary calendar invites. HOLLOWGRAPH is a .NET-compiled malware component that abuses the Microsoft Graph API through a compromised Microsoft 365 account, turning the mailbox’s calendar into a covert two-way “dead drop” for hackers. The malware supports only two commands, get and send, and instead of contacting a suspicious attacker server, it routes everything through trusted Microsoft cloud infrastructure, making the traffic blend in with normal business activity. According to a Group-IB report, the operators plant instructions as calendar events, while the malware exfiltrates stolen files by creating its own encrypted events, with data hidden inside file attachments. To avoid tipping off the mailbox owner, every malicious event is scheduled 24 years into the future, specifically May 13, 2050, so it never appears on anyone’s actual schedule. Sneaky Credential Refresh via DNS Beyond the calendar trick, HOLLOWGRAPH uses a second covert channel: DNS tunneling through IPv6 AAAA record queries to a domain called “cloudlanecdn[.]com”. This lets the malware quietly refresh its Microsoft Entra ID (Azure AD) login credentials , storing the updated values in a file disguised as an innocent log file, logAzure.txt. All data moving through the Graph API channel is protected with hybrid RSA and AES-256-GCM encryption, using separate key pairs for incoming commands and outgoing stolen data so the two directions stay cryptographically isolated. Group-IB attributes HOLLOWGRAPH with high confidence to the Cavern backdoor framework, a modular command-and-control toolkit previously documented by Check Point Research and associated with an Iran-nexus actor tracked as “Cavern Manticore”. The link is based on matching command syntax and shared self-command codes observed in both malware families. Investigators also spotted technical overlaps with Lyceum, an Iranian threat group tied to Iran’s Ministry of Intelligence and Security and considered a sub-group of OilRig, though this connection is held at only low confidence. This isn’t a mass-scale campaign. Group-IB identified just 12 infected systems, with only about three actively communicating with the attackers during the observation window. Activity has been tracked since at least June 3, 2026, with the most recent communication observed on July 9, 2026. Every indicator the compromised mailbox, uploaded malware samples, and related Cavern files points to a narrow focus on Israeli organizations, suggesting a deliberate espionage operation rather than opportunistic hacking. Organizations can hunt for the malware by looking for calendar events dated 2050-05-13, subjects that are bare GUIDs or follow “Event ID:” and “Boss{..}ID{..}” naming patterns, and attachments named File{n}.txt. Security teams should also audit Microsoft Graph activity for application-driven calendar changes, monitor for unusual AAAA DNS queries, and watch for the cloudlanecdn[.]com domain and logAzure.txt file. Group-IB recommends organizations strengthen cloud visibility, monitor for abuse of trusted cloud services, and tighten controls around OAuth application permissions and Entra ID credentials to catch similar attacks early.  Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. ->  Integrate ANY.RUN With Your SOC  Now . The post Hackers Are Turning Microsoft 365 Calendar Invites Into Secret Malware Command Channels appeared first on Cyber Security News .
cybersecuritynews.com
July 20, 2026 at 6:09 PM
HOLLOWGRAPHマルウェア、Microsoft 365のカレンダーをスパイ活動の通信経路に悪用

Group-IBの研究者らが発見したところによると、Microsoft 365のカレンダーがスパイ活動用マルウェアの隠し場所として悪用されており、コマンドや窃取したファイルが2050年という未来の日付が設定された予定に紛れ込ませられていました。 イランのスパイ活動と関連する標的型キャンペーン Grou...
HOLLOWGRAPHマルウェア、Microsoft 365のカレンダーをスパイ活動の通信経路に悪用
Group-IBの研究者らが発見したところによると、Microsoft 365のカレンダーがスパイ活動用マルウェアの隠し場所として悪用されており、コマンドや窃取したファイルが2050年という未来の日付が設定された予定に紛れ込ませられていました。 イランのスパイ活動と関連する標的型キャンペーン Grou
blackhatnews.tokyo
July 20, 2026 at 5:29 PM
HollowGraph Malware Abuses Microsoft 365 Calendars for Covert Command-and-Control #CyberAttacks #datasecurity #DataTheft
HollowGraph Malware Abuses Microsoft 365 Calendars for Covert Command-and-Control
 The malware component HollowGraph is using Microsoft 365 mailbox calendars to hide its C2 channels and traffic, enabling the bad actors to communicate with the malware and exfiltrate the data. Group-IB researchers note that HollowGraph is a part of the Cavern command-and-control framework used by the Iranian nation-state actor previously observed targeting Israeli organizations. Researchers note that at least 12 Microsoft 365 mailboxes were compromised using HollowGraph, and three of them established communication with the attackers’ C2 servers between June 3 and July 9.  Additionally, based on the infrastructure and victims’ location, Group-IB experts suggest that Israel is the likely target of this malware. The HollowGraph malware component is designed to self-register in the Microsoft Graph API using the credentials stolen from the Microsoft 365 mailbox. It stores the configuration data in the logAzure.txt file, which contains the Microsoft Entra ID information, client credentials, mailbox addresses of the victims, domains controlled by the attackers, and keys required to communicate with the C2 infrastructure.  The attackers have taken measures to ensure that this file is not suspicious; specifically, it is placed in the known location used by Microsoft Entra ID and has the standard log file name. The malware communicates with its C2 server using the Microsoft 365 calendars. Specifically, HollowGraph creates events scheduled on May 13, 2050, and uses their titles and attachments to exchange data with the attackers. There are two types of such events: GET and SEND. The first one is used to retrieve the encrypted commands by extracting the contents of the event’s title.  In turn, the SEND type of events is used to exfiltrate the stolen data by adding it as an attachment. Researchers note that the mailbox calendars are used as a “dead drop” to store the data; hence, HollowGraph does not use traditional C2 servers to avoid detection. It implements a strong encryption scheme to protect the command and data exfiltration channels and uses a combination of RSA and AES_256_GCM encryption algorithms. The RSA public key is embedded into the calendar event, whereas the HollowGraph malware uses the AES key to encrypt the data.  Besides the Microsoft Graph API, HollowGraph also uses the Domain Name System (DNS) to communicate with its C2 servers. Specifically, the malware resolves the domains controlled by the attackers to extract the IPv6 AAAA records, which contains the updated Microsoft Entra ID credentials required to maintain persistence on the compromised mailboxes. Similar to the information stored in the logAzure.txt file, these credentials include the Microsoft Entra ID tenant, client ID and secret, and the mailbox information.  All of these credentials are extracted from the DNS responses and stored in the malware configuration. Group-IB researchers conclude that HollowGraph is a sophisticated backdoor that utilizes various cybersecurity technologies to compromise targeted Microsoft 365 mailboxes and remain undetected for as long as possible. While the technical capabilities of this malware component overlaps with the ones attributed to the Lyceum Iranian nation-state actor, the researchers are not certain about its origin.  Nevertheless, Group-IB experts note that there is a high likelihood that HollowGraph belongs to the Cavern framework used by Lyceum. To detect and prevent similar attacks, the cybersecurity experts recommend that organizations monitor the Microsoft Graph API activity and Microsoft 365 audit logs for any suspicious activities related to the creation of the calendar events. Specifically, defenders should pay attention to the events created by applications using the Microsoft Graph API scheduled far in the future, with the suspicious subjects and attachments.  The researchers also recommend that organizations add the cloudlanecdn[.]com domain to their threat intelligence platforms and continuously monitor their Microsoft 365 environments for any unauthorized OAuth client credential applications. In addition, Group-IB experts note that Microsoft Entra ID Conditional Access policies and outbound DNS traffic should be reviewed to detect and block similar恶意 activities, such as DNS tunneling. This report highlights the importance of the growing threat landscape in cloud environments caused by the increasing reliance on the collaborative software in enterprise networks.  Malware components like HollowGraph demonstrate that the attackers do not limit themselves to traditional network security tools and can use the trusted infrastructure to launch attacks against various organizations. In particular, the attackers utilize the cloud infrastructure as a part of their mitigation strategy. In turn, the defenders should shift their focus from traditional network perimeter security to inspecting individual hosts and applications for detecting malicious activities.
dlvr.it
August 2, 2026 at 2:31 PM
HOLLOWGRAPH Backdoor Turns Microsoft 365 Calendars Into a C2 Channel
HOLLOWGRAPH Backdoor Turns Microsoft 365 Calendars Into a C2 Channel
www.picussecurity.com
July 29, 2026 at 10:24 PM