HOLLOWGRAPH Malware Exploits Microsoft 365 Calendars for Espionage

HOLLOWGRAPH Malware Exploits Microsoft 365 Calendars for Espionage

First seen 20 Jul 2026, 13:12 UTC Infosecurity-MagazineThehackernewsTheregisterFeeds.4SysopsFeeds2.Feedburner+4 89% similarity 74.5

Article Content

Browse articles
ThreatCluster

Group-IB has identified HOLLOWGRAPH, a sophisticated Windows malware that abuses the Microsoft Graph API to covertly exfiltrate files and receive commands through compromised Microsoft 365 calendar events. The malware operates by creating calendar appointments dated far into the future, specifically May 13, 2050, to avoid detection. It has been linked to the Cavern backdoor framework and is primarily targeting Israeli entities, with 12 confirmed infections. The malware employs DNS tunneling for credential renewal and uses hybrid RSA and AES encryption for secure communications. The attack method is highly targeted, suggesting a well-resourced adversary, potentially linked to Iranian threat actors. The first observed communication occurred on June 3, 2026, with the latest on July 9, 2026.

Key Points: • HOLLOWGRAPH uses Microsoft 365 calendars for covert command-and-control communications. • The malware targets Israeli entities, with 12 confirmed infections and a focus on espionage. • It employs advanced techniques like DNS tunneling and hybrid encryption to evade detection.

ThreatCluster AI

Timeline

2026-06-03
First observed communication with HOLLOWGRAPH
The earliest communication between a victim and the attacker was recorded on this date.
Infosecurity-Magazine
2026-07-09
Latest communication identified
The most recent communication involving the HOLLOWGRAPH malware was noted on this date.
Infosecurity-Magazine
2026-07-20
HOLLOWGRAPH publicly disclosed
Group-IB released details about the HOLLOWGRAPH malware, outlining its methods and targets.
Group-IB

Community

Browse all →