Microsoft 365 calendars become spy drop boxes in HOLLOWGRAPH campaign

← Back to the feed

Microsoft 365 calendars become spy drop boxes in HOLLOWGRAPH campaign

The Register · 21 hours ago

Researchers at Group-IB have identified a new espionage malware component, dubbed HOLLOWGRAPH, that uses compromised Microsoft 365 calendars as a covert command-and-control channel. Rather than contacting attacker-run servers, the implant reads encrypted instructions from calendar appointments and deposits stolen files into new events for its operators to retrieve, disguising all traffic as ordinary Microsoft Graph API activity. This matters because the technique exploits trusted, legitimate cloud infrastructure rather than a software flaw, making the malware's communications far harder for conventional security tools to detect.

Every malicious calendar entry created by HOLLOWGRAPH is dated 13 May 2050, an obscure slot unlikely to draw attention, and the malware periodically refreshes stolen Entra ID credentials via DNS tunnelling to keep the Graph-based channel working. Group-IB linked the tool to the Cavern framework with high confidence and noted possible, though only weakly supported, ties to the Iranian-linked Lyceum group. The campaign appears narrowly targeted, with just 12 infected systems identified and only three communicating with the compromised mailbox, which belonged to an Israeli organisation; samples were also uploaded from Israel, pointing to a focused intelligence-gathering operation rather than widespread attacks.

  • New HOLLOWGRAPH malware hides spy commands inside Microsoft 365 calendar invites
  • Fake events dated 2050 disguise stolen data and instructions
  • Narrow, targeted campaign linked to an Israeli mailbox, possibly Iran-linked group

Cybersecurity Elections Politics Technology

Read the full article at the source →