The Bottom Line: HollowGraph uses Microsoft Graph API via the calendar feature for command-and-control communication and data exfiltration within legitimate Microsoft 365 accounts.
A new malware component named HollowGraph abuses the calendar function in compromised Microsoft 365 mailboxes as a command-and-control channel to receive attacker commands and exfiltrate data.
The malware component identified as HollowGraph was discovered specifically exploiting calendar functionality in already-compromised Microsoft 365 mailboxes. Instead of using external servers for communication, all data exchange between attacker and malware occurs via the Microsoft Graph API through calendar entries — a channel that operates normally in legitimate enterprise environments and therefore attracts less attention.
For CISOs, this attack method is relevant because it bypasses traditional network-based intrusion detection systems. Command-and-control communication takes place within the organization’s own Microsoft 365 tenant, making it difficult to distinguish between legitimate business traffic and attack traffic. Affected organizations must expect that already-compromised accounts can be remotely controlled without leaving external connection traces.
For detection and mitigation, organizations should monitor audit logs for unusual calendar API access, particularly bulk operations or access outside normal business hours. Additionally, strict conditional access policies for Microsoft Graph permissions are recommended, as well as segmentation of Microsoft 365 administrator accounts from standard user accounts to minimize the risk of compromise.
Source: www.bleepingcomputer.com · Published July 20, 2026
Lumi AI News — AI-assisted curation pursuant to Article 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.