← All stories
● Covered by 3 sources · 3 reportsMedium impact

HollowGraph Malware Utilizes Microsoft 365 Calendars for C2 Communications

🔄 Updated 73d ago — new reporting from SecurityWeek
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • HollowGraph malware uses Microsoft 365 calendar for C2 channels.
  • Events dated 2050 disguise malicious activity as legitimate.
  • Targets Israeli entities, linked to Iranian threat actors.
  • Uses hybrid RSA and AES-256 encryption for data security.
  • Relies on Microsoft Graph API and DNS tunneling for operations.

Overview of HollowGraph Malware

HollowGraph is a newly discovered malware that exploits Microsoft 365 calendar events as a command-and-control (C2) communication channel. The malware utilizes events dated in the far future, specifically 2050, to embed operator instructions and exfiltrate stolen data, evading detection by appearing as legitimate traffic within Microsoft 365 services.

Technical Methodology

The malware, described as a .NET DLL, operates by using compromised Microsoft 365 mailboxes. Through the Microsoft Graph API, it transforms the mailbox's calendar into a two-way dead-drop. Operator commands are sent as attached files in future-dated events, and similarly, stolen data is encrypted and attached to newly created future events. RSA and AES-256 encryption ensures secure communication.

Targeting Specific Entities

Group-IB reports identify that HollowGraph predominantly targets entities within Israel, suggesting a strategic espionage effort. This targeted approach is part of a larger toolkit linked to the Iranian threat actor, Cavern Manticore. The malware reportedly infected at least a dozen systems, with three actively communicating with the threat actor during a monitoring period.

Additional Capabilities

Besides using the Microsoft 365 calendar for C2 communications, HollowGraph maintains a secondary channel for refreshing configurations and credentials via DNS tunneling. This includes associated details like Microsoft Entra ID that support ongoing operations and maintain access to compromised systems.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~34 min · 27 stories · Oct 02

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

The newly discovered HollowGraph malware utilizes Microsoft 365 calendar for command-and-control communication, hiding its activity within legitimate traffic. This innovative approach poses significant security risks, especially to targeted entities in Israel and highlights the evolving tactics of cyber threat actors linked to Iranian interests.

New malware known as HollowGraph leverages Microsoft 365 calendar features for command-and-control communications, primarily targeting Israeli entities. This sophisticated method conceals attacker commands and exfiltrated data within calendar events, indicating a significant advancement in cyber espionage techniques.

A new malware named HollowGraph uses Microsoft 365 calendars to send commands and exfiltrate data. By embedding instructions and stolen files in events set for the year 2050, it disguises its activity as legitimate traffic to evade detection.