CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 2837

As cited

Copy frozen at (site build).

threat intel

HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050

Security researchers at Group-IB discovered HollowGraph, a malware that abuses Microsoft 365 calendar events dated to 2050 to hide command-and-control communications and exfiltrate stolen data through legitimate Microsoft Graph API traffic. The approach allows operators to send tasking instructions and receive stolen files while evading detection that typically focuses on anomalous network communications.

Why it matters: Organizations relying on Microsoft 365 for email and calendar are at risk from this evasion technique; defenders should monitor calendar API activity for unusual patterns and far-future event dates that deviate from normal business use.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050

A newly discovered malware called HollowGraph uses hijacked Microsoft 365 calendars as a command and control channel by posting operator instructions and stolen file attachments on calendar events dated to year 2050. The technique leverages legitimate Microsoft Graph application programming interface (API) traffic, allowing the activity to blend in with normal enterprise communications.

Why it matters: Organizations using Microsoft 365 are at risk from espionage implants that operate through trusted, sanctioned API channels; security teams should monitor for anomalous calendar event activity and implement conditional access controls to detect hijacked accounts.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050

A newly discovered malware called HollowGraph uses hijacked Microsoft 365 calendars as a command and control channel by posting operator instructions and stolen file attachments on calendar events dated to year 2050. The technique leverages legitimate Microsoft Graph application programming interface (API) traffic, allowing the activity to blend in with normal enterprise communications.

Why it matters: Organizations using Microsoft 365 are at risk from espionage implants that operate through trusted, sanctioned API channels; security teams should monitor for anomalous calendar event activity and implement conditional access controls to detect hijacked accounts.

VendorsMicrosoft
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary