As cited
Copy frozen at (site build).
threat intel
HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050
Security researchers at Group-IB discovered HollowGraph, a malware that abuses Microsoft 365 calendar events dated to 2050 to hide command-and-control communications and exfiltrate stolen data through legitimate Microsoft Graph API traffic. The approach allows operators to send tasking instructions and receive stolen files while evading detection that typically focuses on anomalous network communications.
Why it matters: Organizations relying on Microsoft 365 for email and calendar are at risk from this evasion technique; defenders should monitor calendar API activity for unusual patterns and far-future event dates that deviate from normal business use.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050
No summary had been written when this copy was frozen.
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050
A newly discovered malware called HollowGraph uses hijacked Microsoft 365 calendars as a command and control channel by posting operator instructions and stolen file attachments on calendar events dated to year 2050. The technique leverages legitimate Microsoft Graph application programming interface (API) traffic, allowing the activity to blend in with normal enterprise communications.
Why it matters: Organizations using Microsoft 365 are at risk from espionage implants that operate through trusted, sanctioned API channels; security teams should monitor for anomalous calendar event activity and implement conditional access controls to detect hijacked accounts.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050
A newly discovered malware called HollowGraph uses hijacked Microsoft 365 calendars as a command and control channel by posting operator instructions and stolen file attachments on calendar events dated to year 2050. The technique leverages legitimate Microsoft Graph application programming interface (API) traffic, allowing the activity to blend in with normal enterprise communications.
Why it matters: Organizations using Microsoft 365 are at risk from espionage implants that operate through trusted, sanctioned API channels; security teams should monitor for anomalous calendar event activity and implement conditional access controls to detect hijacked accounts.
- Source published
- First seen by Cybersecurity Tracker