ShellCodeX
Tools • Events • News • Insights
ShellCodeX Intelligence Brief
HIGH Cybersecurity

HollowGraph malware uses Microsoft 365 calendar items as command channels

Source headline: New HollowGraph Malware Abuses Microsoft 365 Calendar for C&C Communication

Threat level High
Signal strength 75/100
Source confidence 1 source
Published 4 hours ago

Intelligence Summary

HollowGraph is a malware toolkit that uses a compromised Microsoft 365 account’s calendar as a two-way dead-drop for command-and-control. The malware reads and writes calendar events to exchange messages with its operators. This technique can blend malicious traffic into normal Outlook and calendar activity, reducing the chance of detection. The threat impacts organizations with exposed or compromised Microsoft 365 accounts. Defenders should monitor unusual calendar access patterns and alert on anomalous event creation or updates tied to non-human activity.

Recommended Action

Review affected assets, schedule urgent remediation, and monitor related indicators.

Topics

#command-and-control #microsoft-365 #hollowgraph #calendar-abuse #dead-drop #exchange-outlook
Original reporting SecurityWeek New HollowGraph Malware Abuses Microsoft 365 Calendar for C&C Communication
Open original source