securityonline.info 7/20/2026, 9:21:10 AM · external

HOLLOWGRAPH Malware Hides Command-and-Control in Microsoft 365 Calendars

HOLLOWGRAPH Malware Hides Command-and-Control in Microsoft 365 Calendars
Developing story malware 2 articles tracked
HollowGraph malware exploits Microsoft 365 calendars for covert C2
CyberSIXT Evidence Panel
Primary Source group-ib.com
Threat Actor
🇮🇷 LYCEUM

THE HOLLOWGRAPH malware, linked to the Cavern backdoor framework, exploits the Microsoft Graph API to hide its command-and-control (C2) operations within Microsoft 365 calendar events, specifically dated far into the future (2050). The malware operates via a compromised Microsoft 365 account targeting Israeli entities, allowing for two-way communication disguised as ordinary calendar activity. It supports commands to retrieve and send information, utilizing encryption to secure its operations.

Group-IB's analysis identifies at least 12 infected systems, noting a low-confidence connection to the Iranian Lyceum group. Detection strategies suggest focusing on unusual Graph API activity and monitoring for future-dated calendar entries.

View Primary Source Via securityonline.info

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline