In brief: HollowGraph conceals espionage commands in Microsoft 365 calendars and leverages the legitimate Graph API to evade detection systems.
A newly discovered espionage implant hides command-and-control instructions and stolen files in Microsoft 365 calendar events dated 2050. The tactic uses the legitimate Microsoft Graph API to camouflage malware traffic inconspicuously within normal cloud traffic.
Group-IB identified the malware as HollowGraph and described a hiding pattern that embeds operator instructions and exfiltrated data in calendar events of target organizations. The 2050 date deliberately obscures the events in the timestamp and makes forensic detection through time-based sorting more difficult.
The approach leverages Microsoft Graph API calls to route the hidden commands and data attachments through standard cloud traffic. Since Microsoft 365 is classified as legitimate by most organizations, these activities are not flagged as suspicious. Network detections targeting identified command channels are circumvented because the communication occurs within a trusted SaaS product.
For CISOs, this represents a significant detection gap: standard endpoint detection and response (EDR) and network monitoring do not detect HollowGraph unless specific anomaly analysis of Microsoft Graph usage patterns is performed. Access to calendar APIs, particularly with unusual dates or attachment sizes, should be part of the baseline.
An effective countermeasure requires conditional access policies in Entra ID that restrict calendar API access to authorized devices and users, as well as audit logging on all Microsoft Graph operations. Deviating or rare API patterns require anomaly detection at the application level.
Source: thehackernews.com · Published 20 July 2026
Lumi AI News — AI-assisted curation according to Article 50 EU AI Act. Paraphrase and classification via Lumi News Pipeline v1.7.3.