CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

New HollowGraph Malware Hijacks Microsoft 365 Calendars for Covert C2 Communications

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 6363

As cited

Copy frozen at (site build).

New HollowGraph Malware Hijacks Microsoft 365 Calendars for Covert C2 Communications

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

New HollowGraph Malware Hijacks Microsoft 365 Calendars for Covert C2 Communications

Researchers identified HollowGraph malware connected to the Cavern framework, which exploits Microsoft 365 calendars and the Microsoft Graph application programming interface (API) to establish covert command and control communications. This technique leverages legitimate cloud services to evade detection by blending malicious traffic with normal calendar activity.

Why it matters: Organizations using Microsoft 365 are exposed to this persistence method; defenders should monitor anomalous calendar API activity and review Graph API permissions for compromised accounts.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

New HollowGraph Malware Hijacks Microsoft 365 Calendars for Covert C2 Communications

Researchers identified HollowGraph malware connected to the Cavern framework, which exploits Microsoft 365 calendars and the Microsoft Graph application programming interface (API) to establish covert command and control communications. This technique leverages legitimate cloud services to evade detection by blending malicious traffic with normal calendar activity.

Why it matters: Organizations using Microsoft 365 are exposed to this persistence method; defenders should monitor anomalous calendar API activity and review Graph API permissions for compromised accounts.

VendorsMicrosoft
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary