logo

Microsoft 365 calendars become spy drop boxes in HOLLOWGRAPH campaign

ID: 5c43ffef-2cfa-5106-a8b7-4a840de41d7d

STIX ID: report--5c43ffef-2cfa-5106-a8b7-4a840de41d7d

Feed Name: The Register (Security)

Threat Score
70/100

Date Published: 2026-07-20

Date Updated: 2026-07-23

...
...

Microsoft 365 calendars are being abused by a malware component named HOLLOWGRAPH that hides encrypted commands and stolen files inside calendar events (all dated May 13, 2050) and uses legitimate Microsoft Graph API requests plus periodic DNS tunneling to refresh Entra ID credentials, enabling stealthy command-and-control and data exfiltration; Group-IB links it to the Cavern framework, notes low-confidence similarity to Lyceum, and observed a narrow, targeted campaign affecting 12 systems.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.