Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
HollowGraph Malware Exploits Microsoft 365 Calendars

HollowGraph Malware Exploits Microsoft 365 Calendars

Posted on July 20, 2026 By CWS

A new type of malware, dubbed HollowGraph, has been identified exploiting Microsoft 365 calendars to conduct espionage operations. The malicious software manipulates calendar events, setting them far into the future, specifically to the year 2050, to avoid detection while using these events to exchange stolen data and commands.

How HollowGraph Operates

The cybersecurity firm Group-IB has brought to light this innovative method, where the malware leverages legitimate Microsoft Graph API traffic to mask its activities as normal Microsoft 365 usage. The malware, a .NET DLL, executes two primary commands: ‘get’ and ‘send’. It uses the compromised calendar as a medium for exchanging information, eliminating the need to connect with an attacker-controlled server for instructions.

To receive commands, HollowGraph queries for an event dated 2050-05-13, ensuring it remains unnoticed in the mailbox. Instructions are embedded in this event as attachments. For data exfiltration, the malware encrypts stolen data, creates a similar future-dated event, and uploads the encrypted files as attachments.

Encryption and Persistence Mechanisms

All data moving through the calendar is secured using hybrid RSA and AES-256 encryption, with separate keys for incoming and outgoing data. Additionally, HollowGraph sustains its access by refreshing its application credentials through DNS, using values decoded from IPv6 records returned by a malicious domain. These credentials are stored in a file disguised as a regular log, keeping the malware’s operations under the radar.

Despite its sophistication, the malware maintains clear communication channels, making it challenging to detect. Group-IB associates HollowGraph with the Cavern backdoor framework, linked to Iranian cyber actors, but stops short of directly attributing it to any specific group.

Detection and Security Measures

HollowGraph’s stealthy use of Microsoft services poses a significant detection challenge. Group-IB suggests monitoring calendar events for unusual characteristics, such as future dates and specific naming patterns, to identify potential indicators of compromise.

On the security front, Group-IB advises organizations to restrict and audit OAuth applications with access to Microsoft Graph, ensuring robust identity management practices. It’s crucial to monitor for unexpected application-driven changes within Microsoft 365 environments and watch for unusual DNS queries that might signal malicious activity.

While HollowGraph is not exploiting any specific software vulnerability, the campaign underscores the importance of vigilant identity and application permission monitoring. As the malware remains active, organizations are encouraged to review their detection strategies and bolster their defenses against such innovative threats.

The Hacker News Tags:Cavern Manticore, cyber defense, cyber threat, Cybersecurity, Encryption, Espionage, Graph API, Group-IB, HollowGraph, Iranian cyber activity, Lyceum, Malware, Microsoft 365, OilRig

Post navigation

Previous Post: TELEPUZ Malware Tactics Exploit ClickFix for 36 Commands
Next Post: SonicWall Zero-Days Exploited Before Patch Release

Related Posts

Key Insights from the 2025 State of Pentesting Report Key Insights from the 2025 State of Pentesting Report The Hacker News
Google Launches OSS Rebuild to Expose Malicious Code in Widely Used Open-Source Packages Google Launches OSS Rebuild to Expose Malicious Code in Widely Used Open-Source Packages The Hacker News
APT28 Exploits MSHTML Vulnerability Before February 2026 Patch APT28 Exploits MSHTML Vulnerability Before February 2026 Patch The Hacker News
Microsoft Locks Down IE Mode After Hackers Turned Legacy Feature Into Backdoor Microsoft Locks Down IE Mode After Hackers Turned Legacy Feature Into Backdoor The Hacker News
Enhancing Incident Response: Key Operational Essentials Enhancing Incident Response: Key Operational Essentials The Hacker News
Stock Exchange Executive’s Email Hacked for Months Stock Exchange Executive’s Email Hacked for Months The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Microsoft Defender XDR Vulnerability in Network Detection
  • HollowGraph Malware Exploits Microsoft 365 Calendar for C&C
  • SonicWall Flaws Exploited to Deploy Malware
  • Estée Lauder Faces Data Breach from Oracle Zero-Day Attack
  • Meta Awards $78,000 for Major Support Data Vulnerability

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Microsoft Defender XDR Vulnerability in Network Detection
  • HollowGraph Malware Exploits Microsoft 365 Calendar for C&C
  • SonicWall Flaws Exploited to Deploy Malware
  • Estée Lauder Faces Data Breach from Oracle Zero-Day Attack
  • Meta Awards $78,000 for Major Support Data Vulnerability

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark