HOLLOWGRAPH Malware Exploits Microsoft 365 Calendars for Espionage
ID: 619a11eb-f2f0-5453-97e4-12c3578987ab
STIX ID: report--619a11eb-f2f0-5453-97e4-12c3578987ab
Feed Name: ThreatCluster
Threat Score
## Executive summary HOLLOWGRAPH is a sophisticated Windows malware campaign that abuses the Microsoft Graph API and Microsoft 365 calendar appointments (appointments dated far in the future) to receive commands and exfiltrate files; it's linked to the Cavern backdoor, uses DNS tunneling for credential renewal, and hybrid RSA/AES encryption, with 12 confirmed Israeli infections observed between 3 June and 9 July 2026 and suspected nation-state (possible Iranian) attribution.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
