www.group-ib.com
HOLLOWGRAPH Malware Exploits Microsoft 365 Calendars for Espionage
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Group-IB has identified HOLLOWGRAPH, a sophisticated Windows malware that abuses the Microsoft Graph API to covertly exfiltrate files and receive commands through compromised Microsoft 365 calendar events. The malware operates by creating calendar appointments dated far into the future, specifically May 13, 2050, to avoid detection. It has been linked to the Cavern backdoor framework and is primarily targeting Israeli entities, with 12 confirmed infections. The malware employs DNS tunneling for credential renewal and uses hybrid RSA and AES encryption for secure communications. The attack method is highly targeted, suggesting a well-resourced adversary, potentially linked to Iranian threat actors. The first observed communication occurred on June 3, 2026, with the latest on July 9, 2026.
Key Points: • HOLLOWGRAPH uses Microsoft 365 calendars for covert command-and-control communications. • The malware targets Israeli entities, with 12 confirmed infections and a focus on espionage. • It employs advanced techniques like DNS tunneling and hybrid encryption to evade detection.