← All stories
● Covered by 2 sources · 2 reportsMedium impact

HollowGraph Malware Uses Microsoft 365 Calendar as Stealthy C2 Channel

🔄 Updated 11h ago — new reporting from BleepingComputer

The newly discovered HollowGraph malware uses Microsoft 365 calendar events set in the year 2050 for stealthy command-and-control (C2) communications. The malware, infecting at least 12 systems and linked to an Iranian threat actor, conceals commands and exfiltrated data through Microsoft Graph API traffic to evade detection. With a focus on Israeli targets, the malware signifies an advancement in cyber espionage techniques.

Key points

  • HollowGraph uses Microsoft 365 calendar events for C2.
  • Events set in 2050 to disguise malware activity.
  • Malware linked to Iranian threat group targeting Israel.
  • At least 12 systems infected with HollowGraph.
  • Uses Microsoft Graph API for command delivery.

Overview of HollowGraph Malware

HollowGraph is a newly identified malware that cleverly leverages Microsoft 365's calendar feature to carry out command-and-control (C2) operations, camouflaging its activities as legitimate network traffic. The malware employs future-dated calendar events, specifically the year 2050, to deceive security systems and users.

Embedded in these calendar entries are espionage commands and exfiltrated data, allowing the malware to operate undetected under the facade of routine Microsoft Graph API communications.

Technological Mechanics

HollowGraph's operative way involves a .NET DLL that connects to compromised Microsoft 365 accounts using hardcoded login credentials. This configuration includes authentication details for the Graph API, masking as a standard logAzure.txt log file to avoid suspicion.

The operations encompass encrypting data with hybrid RSA and AES-256 encryption, uploading it discreetly through far-future calendar events. Commands and data are extracted and embedded in events set decades ahead to ensure they remain unnoticed by mailbox owners.

Targeted Cyber Espionage

Linked to a known Iranian threat actor, the malware has been especially active in espionage campaigns against Israeli institutions. At least 12 systems have been confirmed infected, with some actively engaging in communications with threat actors from early June to mid-July.

This activity underscores the tool’s role in broader espionage initiatives, underlining its significance for national security and information protection in the region.

Implications for Cybersecurity

HollowGraph represents an innovative step in malware development, with the ability to use legitimate services like Microsoft 365 for covert operations posing significant challenges for cybersecurity experts.

The utilization of conventional platforms for malicious purposes necessitates advanced detection and response strategies, especially in politically sensitive landscapes like Israeli entities targeted by state-linked actors.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~23 min · 20 stories · Jul 20

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

New malware known as HollowGraph leverages Microsoft 365 calendar features for command-and-control communications, primarily targeting Israeli entities. This sophisticated method conceals attacker commands and exfiltrated data within calendar events, indicating a significant advancement in cyber espionage techniques.

A new malware named HollowGraph uses Microsoft 365 calendars to send commands and exfiltrate data. By embedding instructions and stolen files in events set for the year 2050, it disguises its activity as legitimate traffic to evade detection.