importantSYS.SOURCE: The Hacker News• 2026-07-20T20:03:43+05:30
HollowGraph Malware Exploits Microsoft 365 Calendar Events for Command and Control
HollowGraph malware uses Microsoft 365 calendar events with 2050 dates to hide command-and-control communications and exfiltrate stolen files through encrypted attachments. It is linked to the Cavern threat group and exploits legitimate Graph API traffic to avoid detection.
A newly discovered espionage implant has been using a hijacked Microsoft 365 calendar as its command channel, planting operator instructions and smuggling out stolen files as attachments on calendar events dated to the year 2050.
Group-IB, which named the malware HollowGraph, says the approach moves tasking and stolen data through legitimate Microsoft Graph API traffic, so the activity looks
*** END OF TRANSMISSION ***