logo

HOLLOWGRAPH Malware Exploits Microsoft 365 Calendars for Espionage

ID: 619a11eb-f2f0-5453-97e4-12c3578987ab

STIX ID: report--619a11eb-f2f0-5453-97e4-12c3578987ab

Feed Name: ThreatCluster

Threat Score
75/100

Date Published: 2026-07-20

Date Updated: 2026-07-20

...
...

## Executive summary HOLLOWGRAPH is a sophisticated Windows malware campaign that abuses the Microsoft Graph API and Microsoft 365 calendar appointments (appointments dated far in the future) to receive commands and exfiltrate files; it's linked to the Cavern backdoor, uses DNS tunneling for credential renewal, and hybrid RSA/AES encryption, with 12 confirmed Israeli infections observed between 3 June and 9 July 2026 and suspected nation-state (possible Iranian) attribution.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.