New HollowGraph Malware Uses Microsoft Graph for Stealthy C2 Comms
Group-IB said the .NET implant hid tasking and stolen files in Outlook calendar events while refreshing credentials through DNS tunneling.
- Researchers from Group-IB discovered HOLLOWGRAPH, a malware component that abuses the Microsoft Graph API to turn Microsoft calendars into a covert "dead drop" for espionage, stashing stolen files and commands in appointments dated May 13, 2050.
- HOLLOWGRAPH avoids exploiting specific software flaws, instead blending into legitimate cloud traffic by wrapping malicious command-and-control requests within standard Microsoft Graph API calls that resemble regular Microsoft application activity.
- Group-IB identified 12 infected systems during observation, with the malware retrieving Entra credentials over a DNS tunneling channel while fetching instructions from calendar events and depositing stolen files into new appointments.
- The compromised mailbox belonged to an Israeli organization with samples uploaded from Israel; Group-IB noted similarities to the Iranian-linked espionage group Lyceum, though researchers expressed only low confidence in that attribution.
- Investigators linked HOLLOWGRAPH to the Cavern framework with high confidence, citing matching command formats; the evidence suggests this operation functions as a focused espionage campaign rather than a broad, indiscriminate attack.
11 Articles
11 Articles
Watch out - that Microsoft Calendar invite dated 2050 could be hiding stolen files and worse
Group‑IB discovers HollowGraph malware targeting Israeli entities, exfiltrating files via Microsoft Graph APIOperators hide instructions in future calendar entries, then attach encrypted stolen data to eventsAt least 12 systems were compromised; overlaps with Lyceum noted but attribution remains low‑confidenceCybercriminals have found a way to communicate with the malware installed on victim devices through compromised Microsoft Calendar apps, e…
Microsoft 365 calendars become spy drop boxes in HOLLOWGRAPH campaign
Microsoft 365 calendars have become the latest hiding place for espionage malware, with attackers stashing commands and stolen files inside appointments dated 24 years into the future. Researchers at Group-IB say they've uncovered a malware component they call HOLLOWGRAPH that swaps the usual command-and-control server for something rather less conspicuous – a compromised Microsoft 365 calendar. Instead of reaching out to attacker-controlled inf…
New HollowGraph malware uses Microsoft Graph for stealthy C2 comms
A malicious component dubbed HollowGraph uses the calendar feature in compromised Microsoft 365 mailboxes as a command-and-control channel to receive attacker commands and exfiltrate stolen data.
Researchers Discover HOLLOWGRAPH Malware Abusing Microsoft 365, Graph API
Key Takeaways: HOLLOWGRAPH hides commands and stolen data within Microsoft 365 calendar events. The malware uses Microsoft Graph API and DNS tunneling to maintain access and retrieve credentials. Researchers linked the activity to a targeted cyber-espionage campaign focused on Israeli organizations. Group-IB researchers have discovered HOLLOWGRAPH, a sophisticated malware linked with high confidence to the Cavern cyber-espionage framework. The …
HollowGraph malware represents a new generation of advanced threats that exploit legitimate cloud computing services to hide malicious activities. Instead of relying on traditional (C2) command and control servers, easily blocked by security solutions, this threat uses Microsoft 365's daily resources, transforming calendar events and the Microsoft Graph API into discrete channels to receive instructions and transmit stolen information. This appr…
Hackers Are Turning Microsoft 365 Calendar Invites Into Secret Malware Command Channels
A stealthy new malware strain called HOLLOWGRAPH that hijacks Microsoft 365 calendars to secretly communicate with hackers, disguising malicious commands as ordinary calendar invites. HOLLOWGRAPH is a .NET-compiled malware component that abuses the Microsoft Graph API through a compromised Microsoft 365 account, turning the mailbox’s calendar into a covert two-way “dead drop” for hackers. The malware supports only two commands, get and send, and…
Coverage Details
Bias Distribution
- 100% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium





