Logo
News Ababil
Explore
SYS_NODE: ONLINE // Cyber Security

HollowGraph Malware Hijacks Microsoft 365 Calendar to Funnel Data to 2050

DECRYPTED BY: Kaelen Frost | TIMESTAMP: 2026-07-20 T 21:20:18 Z | [ 1 MIN READ ]
HollowGraph Malware Hijacks Microsoft 365 Calendar to Funnel Data to 2050
1 Min Read
Share

HollowGraph malware uses Microsoft 365 calendar as C2 channel

The newly uncovered HollowGraph malware has turned a Microsoft 365 calendar into a covert command‑and‑control conduit, slipping operator instructions and exfiltrated documents into events stamped for the year 2050. By embedding malicious payloads as calendar attachments, the implant blends with ordinary Graph API calls, making network monitoring almost blind.

How 2050‑dated events conceal stolen files

Security researchers at Group‑IB observed that the malware leverages the Microsoft Graph endpoint to post events that appear legitimate to administrators.

“We observed the implant leveraging the Graph API to blend malicious traffic with legitimate requests,” a Group‑IB analyst told Reuters.

This technique masks data exfiltration behind calendar invites, with attachments automatically synchronized to victim devices.

Detection remains low, reflected by a ↓ 0% detection rate across major AV platforms. Analysts warn that similar tactics could surface in post‑pandemic threat landscapes, urging enterprises to tighten Graph API audit logs.

Intel provided by: Kaelen Frost
Lead Cybersecurity Analyst
Global Data Feed

More from this Intel

Merger & Acquisition scams: How fraudsters target large enterprises with fake deals

Merger & Acquisition scams: How fraudsters target large enterprises with...

Sep 04, 2026
French hospital fined €500,000 after massive data breach

French hospital fined €500,000 after massive data breach

Sep 04, 2026
Palo Alto Networks acquisition of Thrive-backed Console valued at $500M

Palo Alto Networks acquisition of Thrive-backed Console valued at $500M

Sep 03, 2026
Silver Fox Unleashes ValleyRAT backdoor via Signed Chinese Adware to Slip Past AV Exclusions

Silver Fox Unleashes ValleyRAT backdoor via Signed Chinese Adware to...

Sep 01, 2026
Why Identity and Permissions Alone Can’t Govern AI Agent Behavior

Why Identity and Permissions Alone Can’t Govern AI Agent Behavior

Aug 31, 2026
Microsoft Defender antivirus turned off – Why users should ignore the alert

Microsoft Defender antivirus turned off – Why users should ignore...

Aug 31, 2026

Join The Elite

Get the top 0.1% global intelligence and market insights delivered directly to your inbox before the masses.

We respect your privacy. No spam.