www.infosecurity-magazine.com 7/20/2026, 12:51:27 PM · external

New HollowGraph Malware Hijacks Microsoft 365 Calendars for Covert C2 Communications

New HollowGraph Malware Hijacks Microsoft 365 Calendars for Covert C2 Communications
Developing story malware 2 articles tracked
HollowGraph malware exploits Microsoft 365 calendars for covert C2
CyberSIXT Evidence Panel
Primary Source group-ib.com

A new malware named HollowGraph has been discovered, which exploits the Microsoft Graph API to transform compromised Microsoft 365 calendars into covert two-way command and control (C2) channels. Researchers from Group-IB identified this malware as part of a targeted operation against Israeli entities, revealing that it is linked to the Cavern backdoor framework. HollowGraph operates through trusted Microsoft services, evading detection by using encrypted communication and DNS tunneling.

Key commands include scheduling appointments with stolen files attached and downloading instructions from planted appointments. Group-IB recommends monitoring Microsoft Graph API activities to identify anomalies.

View Primary Source Via www.infosecurity-magazine.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline