www.securityweek.com 7/21/2026, 12:31:41 PM · external

HollowGraph malware hijacks Microsoft 365 calendar for covert C2

HollowGraph malware hijacks Microsoft 365 calendar for covert C2
Developing story malware 3 articles tracked
HollowGraph malware exploits Microsoft 365 calendar for covert command-and-control
CyberSIXT Evidence Panel
Primary Source group-ib.com
Threat Actor
Cavern Manticore

A newly identified malware called HollowGraph utilizes the Microsoft 365 calendar for command-and-control communication, as reported by Group-IB. This malware, linked to the Iran-nexus threat actor Cavern Manticore, obscures its activities by hiding within legitimate traffic via the Microsoft Graph API.

The malware uses a compromised 365 account in Israel and employs a unique method of data exfiltration and tasking through calendar events, which are triggered by the malware creating future-dated events to avoid detection. HollowGraph has affected specific Israeli targets and operates through a low-confidence attribution to the Iran-linked Lyceum subgroup. The malware features hybrid encryption and retains a secondary DNS tunneling channel for updated configurations.

View Primary Source Via www.securityweek.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline