Logo
News Ababil
Explore
SYS_NODE: ONLINE // Cyber Security

HollowGraph Malware Hijacks Microsoft 365 Calendar to Funnel Data to 2050

DECRYPTED BY: Kaelen Frost | TIMESTAMP: 2026-07-20 T 21:20:18 Z | [ 1 MIN READ ]
HollowGraph Malware Hijacks Microsoft 365 Calendar to Funnel Data to 2050
1 Min Read
Share

HollowGraph malware uses Microsoft 365 calendar as C2 channel

The newly uncovered HollowGraph malware has turned a Microsoft 365 calendar into a covert command‑and‑control conduit, slipping operator instructions and exfiltrated documents into events stamped for the year 2050. By embedding malicious payloads as calendar attachments, the implant blends with ordinary Graph API calls, making network monitoring almost blind.

How 2050‑dated events conceal stolen files

Security researchers at Group‑IB observed that the malware leverages the Microsoft Graph endpoint to post events that appear legitimate to administrators.

“We observed the implant leveraging the Graph API to blend malicious traffic with legitimate requests,” a Group‑IB analyst told Reuters.

This technique masks data exfiltration behind calendar invites, with attachments automatically synchronized to victim devices.

Detection remains low, reflected by a ↓ 0% detection rate across major AV platforms. Analysts warn that similar tactics could surface in post‑pandemic threat landscapes, urging enterprises to tighten Graph API audit logs.

Intel provided by: Kaelen Frost
Lead Cybersecurity Analyst
Global Data Feed

More from this Intel

AI safety guardrails blocked defenders, not attackers, in Hugging Face breach

AI safety guardrails blocked defenders, not attackers, in Hugging Face...

Jul 20, 2026
Zero‑Day WordPress Core Flaw Exposes Sites to Unauthenticated Code Execution

Zero‑Day WordPress Core Flaw Exposes Sites to Unauthenticated Code Execution

Jul 19, 2026
Capital One Unveils VulnHunter: Open‑Source AI Tool to Preempt Software Exploits

Capital One Unveils VulnHunter: Open‑Source AI Tool to Preempt Software...

Jul 18, 2026
Brex Reinvents AI Agent Policy with Network‑Level Enforcement, Not Pre‑Written Rules

Brex Reinvents AI Agent Policy with Network‑Level Enforcement, Not Pre‑Written...

Jul 18, 2026
SonicWall SMA zero-day exploited by Inc ransomware

SonicWall SMA zero-day exploited by Inc ransomware

Jul 18, 2026
Brian Chesky X Hack Exposes AI‑Generated Crypto Spam on CEO’s Account

Brian Chesky X Hack Exposes AI‑Generated Crypto Spam on CEO’s...

Jul 17, 2026

Join The Elite

Get the top 0.1% global intelligence and market insights delivered directly to your inbox before the masses.

We respect your privacy. No spam.