By Interestana AI Editorial — AI-drafted, human-overseen. How we report
HollowGraph Malware Uses Microsoft 365 Calendar for C2

A novel espionage implant, identified as HollowGraph by cybersecurity firm Group-IB, has been discovered utilizing hijacked Microsoft 365 calendars to establish its command and control (C2) channel. This sophisticated malware embeds operator instructions and smuggles stolen files by attaching them to calendar events scheduled for the distant future, specifically the year 2050. This technique allows HollowGraph to disguise its malicious activities as legitimate Microsoft Graph API traffic, making detection significantly more challenging.
The malware's operational method involves creating or manipulating calendar events within a compromised Microsoft 365 tenant. These events serve a dual purpose: receiving instructions from the attackers and transmitting exfiltrated data back to them. By scheduling these events far into the future, the attackers create a persistent, albeit delayed, communication channel that blends seamlessly with normal user activity. The use of the Microsoft Graph API, a legitimate interface for accessing Microsoft 365 data, further obfuscates the malicious operations, making it difficult for security tools to distinguish between genuine calendar entries and those used for C2 communication.
Group-IB's analysis indicates that HollowGraph's primary objective is espionage, focusing on stealing sensitive information from targeted organizations. The malware's ability to hide both its command infrastructure and its data exfiltration within a widely used cloud service like Microsoft 365 represents a significant advancement in stealthy cyberattack techniques. The future-dated events act as a covert data-smuggling mechanism, where sensitive files are attached and delivered at a predetermined future time, or when an attacker manually triggers their retrieval through subsequent calendar manipulations. This method bypasses traditional network security controls that might flag direct data transfers.
The discovery of HollowGraph highlights the evolving tactics of advanced persistent threats (APTs) and the increasing reliance on cloud-native functionalities for malicious purposes. Security researchers are now focused on developing detection strategies that can identify anomalies within Microsoft Graph API usage and calendar event patterns, even when they appear to be legitimate. The year 2050 date serves as a strong indicator of malicious intent, but the underlying mechanism of using legitimate API calls for covert operations remains a critical concern for cloud security.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.