HollowGraph espionage implant uses Microsoft 365 calendar events as C2
Source headline: HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050
Intelligence Summary
Group-IB reports the HollowGraph espionage implant uses a hijacked Microsoft 365 calendar as its command channel. Operator instructions are delivered through legitimate Microsoft Graph API traffic. The malware also smuggles stolen files out by attaching them to calendar events timestamped for the year 2050. This blending into normal productivity data can make detection harder for defenders monitoring email and Graph activity. Organizations using Microsoft 365 should review unusual calendar changes and Graph API access patterns tied to unexpected accounts or apps.
Recommended Action
Review affected assets, schedule urgent remediation, and monitor related indicators.