Hollowgraph malware turns Microsoft 365 calendars into covert spy channels

Group-IB discovered HOLLOWGRAPH, malware that uses Microsoft 365 calendars as covert command channels with events dated to 2050.

CSBadmin
2 Min Read

Researchers at Group-IB have uncovered a malware component called HOLLOWGRAPH that replaces the traditional command-and-control server with compromised Microsoft 365 calendars, stashing encrypted tasking inside appointments dated May 13, 2050.

Rather than reaching out to attacker-controlled infrastructure for instructions, the implant rummages through calendar events using the Microsoft Graph API, picks up encrypted commands, and drops stolen files into new appointments for operators to collect later. Every event created by HOLLOWGRAPH uses the year 2050 to keep malicious entries tucked away in an otherwise empty corner of the diary.

The malware itself is lean. It fetches instructions from one calendar event, stashes exfiltrated data in another, and periodically retrieves fresh Entra ID credentials over a DNS tunneling channel so the Graph-based communications keep working. Group-IB found 12 infected systems, three of which actively communicated with the compromised mailbox during the observation period.

The research team linked HOLLOWGRAPH to the Cavern framework with high confidence based on matching command formats and implementation details. They noted similarities with the Iranian-linked espionage group Lyceum but stopped short of a definitive attribution.

HOLLOWGRAPH does not exploit any vulnerability in Microsoft 365 or Graph. It abuses services already trusted inside organizations, making its activity far less conspicuous than malware that calls home to external infrastructure. Defenders should monitor for calendar entries with anomalous dates and unusual Graph API activity from non-standard applications.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.