logo

HOLLOWGRAPH malware turns Microsoft 365 calendars into an espionage channel

ID: a4aea306-b1e4-52fc-99e1-3a96aa0850f4

STIX ID: report--a4aea306-b1e4-52fc-99e1-3a96aa0850f4

Feed Name: Help Net Security

Threat Score
75/100

Date Published: 2026-07-20

Date Updated: 2026-07-20

Author: Sinisa Markovic

...
...

Group-IB discovered HOLLOWGRAPH, an espionage malware that uses Microsoft 365 calendar events and the Graph API to receive commands and exfiltrate encrypted files (attachments dated in 2050), while using DNS-based IPv6 lookups for credential renewal; they link it to the Cavern modular backdoor and observe 12 infected systems (targeting Israeli entities) active June–July 2026, and provide IOCs and detection guidance for Microsoft 365/Entra ID.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.