HollowGraph malware uses Microsoft 365 calendar items as command channels
Source headline: New HollowGraph Malware Abuses Microsoft 365 Calendar for C&C Communication
Intelligence Summary
HollowGraph is a malware toolkit that uses a compromised Microsoft 365 account’s calendar as a two-way dead-drop for command-and-control. The malware reads and writes calendar events to exchange messages with its operators. This technique can blend malicious traffic into normal Outlook and calendar activity, reducing the chance of detection. The threat impacts organizations with exposed or compromised Microsoft 365 accounts. Defenders should monitor unusual calendar access patterns and alert on anomalous event creation or updates tied to non-human activity.
Recommended Action
Review affected assets, schedule urgent remediation, and monitor related indicators.