HollowGraph Malware Hides C2 Commands in Microsoft 365 Calendar Events
Cybersecurity firm Group-IB disclosed on July 20, 2026, a new espionage implant called HollowGraph that conceals its command-and-control channel inside Microsoft 365 calendar entries. The malware attaches encrypted files to calendar events dated May 13, 2050, retrieving operator instructions from that far-future dead-drop via the Microsoft Graph API, making its traffic appear indistinguishable from normal M365 activity. At least 12 systems have been infected, with three actively communicating with the threat actor between June 3 and July 9, 2026, in a campaign targeting Israeli organizations. HollowGraph also uses DNS tunneling over IPv6 AAAA records from an attacker-controlled domain to refresh its Azure AD credentials. Group-IB linked the implant with high confidence to the Cavern backdoor framework, previously associated with Iranian-nexus threat activity, though definitive attribution has not been established.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in