logo

Hackers Are Turning Microsoft 365 Calendar Invites Into Secret Malware Command Channels

ID: 266509f2-df3d-583e-bfd6-d938b0e3e855

STIX ID: report--266509f2-df3d-583e-bfd6-d938b0e3e855

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-07-20

Date Updated: 2026-07-20

Author: Guru Baran

...
...

A Group-IB report details HOLLOWGRAPH, a .NET malware that hijacks Microsoft 365 calendars via the Microsoft Graph API to receive commands and exfiltrate encrypted data inside calendar event attachments, while using IPv6 AAAA DNS queries to cloudlanecdn.com to refresh Entra ID credentials saved to a disguised logAzure.txt file. The operators schedule malicious events for May 13, 2050 to avoid user notice; activity (12 infected hosts, ~3 actively communicating) was observed June–July 2026 and appears focused on Israeli organizations. Group-IB links HOLLOWGRAPH to the Cavern backdoor/Cavern Manticore framework (high confidence), notes low-confidence overlaps with Lyceum/OilRig, and provides IoCs (event naming patterns, File{n}.txt attachments, cloudlanecdn.com, logAzure.txt, unusual AAAA queries) plus detection and mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.