logo

New HollowGraph Malware Hijacks Microsoft 365 Calendars for Covert C2 Communications

ID: 9da25b1b-09f8-5dd0-80cc-593aa14486d6

STIX ID: report--9da25b1b-09f8-5dd0-80cc-593aa14486d6

Feed Name: Infosecurity Magazine (News)

Threat Score
78/100

Date Published: 2026-07-20

Date Updated: 2026-07-20

...
...

Researchers at Group-IB identified a sophisticated Windows malware called HollowGraph that uses Microsoft Graph API and Microsoft 365 calendar appointments (attachments) to implement a covert two-way C2 channel, delivering and receiving encrypted payloads and instructions; it also uses DNS tunneling to manage Azure AD credentials. The activity, linked by technical indicators to the Cavern framework and displaying similarities to the Lyceum actor, appears highly targeted at Israeli organizations with 12 infected systems observed between June 3 and July 9, 2026, prompting recommendations to monitor Graph API and mailbox calendar operations for anomalies.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.