Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
HollowGraph Malware Exploits Microsoft 365 Calendars

HollowGraph Malware Exploits Microsoft 365 Calendars

Posted on July 20, 2026 By CWS

A new type of malware, dubbed HollowGraph, has been identified exploiting Microsoft 365 calendars to conduct espionage operations. The malicious software manipulates calendar events, setting them far into the future, specifically to the year 2050, to avoid detection while using these events to exchange stolen data and commands.

How HollowGraph Operates

The cybersecurity firm Group-IB has brought to light this innovative method, where the malware leverages legitimate Microsoft Graph API traffic to mask its activities as normal Microsoft 365 usage. The malware, a .NET DLL, executes two primary commands: ‘get’ and ‘send’. It uses the compromised calendar as a medium for exchanging information, eliminating the need to connect with an attacker-controlled server for instructions.

To receive commands, HollowGraph queries for an event dated 2050-05-13, ensuring it remains unnoticed in the mailbox. Instructions are embedded in this event as attachments. For data exfiltration, the malware encrypts stolen data, creates a similar future-dated event, and uploads the encrypted files as attachments.

Encryption and Persistence Mechanisms

All data moving through the calendar is secured using hybrid RSA and AES-256 encryption, with separate keys for incoming and outgoing data. Additionally, HollowGraph sustains its access by refreshing its application credentials through DNS, using values decoded from IPv6 records returned by a malicious domain. These credentials are stored in a file disguised as a regular log, keeping the malware’s operations under the radar.

Despite its sophistication, the malware maintains clear communication channels, making it challenging to detect. Group-IB associates HollowGraph with the Cavern backdoor framework, linked to Iranian cyber actors, but stops short of directly attributing it to any specific group.

Detection and Security Measures

HollowGraph’s stealthy use of Microsoft services poses a significant detection challenge. Group-IB suggests monitoring calendar events for unusual characteristics, such as future dates and specific naming patterns, to identify potential indicators of compromise.

On the security front, Group-IB advises organizations to restrict and audit OAuth applications with access to Microsoft Graph, ensuring robust identity management practices. It’s crucial to monitor for unexpected application-driven changes within Microsoft 365 environments and watch for unusual DNS queries that might signal malicious activity.

While HollowGraph is not exploiting any specific software vulnerability, the campaign underscores the importance of vigilant identity and application permission monitoring. As the malware remains active, organizations are encouraged to review their detection strategies and bolster their defenses against such innovative threats.

The Hacker News Tags:Cavern Manticore, cyber defense, cyber threat, Cybersecurity, Encryption, Espionage, Graph API, Group-IB, HollowGraph, Iranian cyber activity, Lyceum, Malware, Microsoft 365, OilRig

Post navigation

Previous Post: TELEPUZ Malware Tactics Exploit ClickFix for 36 Commands
Next Post: SonicWall Zero-Days Exploited Before Patch Release

Related Posts

CISA Urges Fortinet Users to Secure Devices Amid Attack CISA Urges Fortinet Users to Secure Devices Amid Attack The Hacker News
China-Linked Amaranth-Dragon Exploits WinRAR Flaw in Southeast Asia China-Linked Amaranth-Dragon Exploits WinRAR Flaw in Southeast Asia The Hacker News
Over 100,000 WordPress Sites at Risk from Critical CVSS 10.0 Vulnerability in Wishlist Plugin Over 100,000 WordPress Sites at Risk from Critical CVSS 10.0 Vulnerability in Wishlist Plugin The Hacker News
Ghostwriter Intensifies Phishing Attacks on Ukraine Ghostwriter Intensifies Phishing Attacks on Ukraine The Hacker News
CISA Orders Immediate Patch of Critical Sitecore Vulnerability Under Active Exploitation CISA Orders Immediate Patch of Critical Sitecore Vulnerability Under Active Exploitation The Hacker News
Turning Disruptive Technology into a Strategic Advantage Turning Disruptive Technology into a Strategic Advantage The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Cyberattack Turns Telegram Bots Into Covert Control System
  • Furtex: Advanced Linux Toolkit for Security Experts
  • Critical PAN-OS Flaw Leads to Qilin Ransomware Attacks
  • Microsoft’s KB5121767 Update Resolves Dell USB-C Issues
  • LG Monitor Software May Install Adware Silently

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Cyberattack Turns Telegram Bots Into Covert Control System
  • Furtex: Advanced Linux Toolkit for Security Experts
  • Critical PAN-OS Flaw Leads to Qilin Ransomware Attacks
  • Microsoft’s KB5121767 Update Resolves Dell USB-C Issues
  • LG Monitor Software May Install Adware Silently

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark