Microsoft Graph API - Tool

Threat entity extracted from intelligence sources

Frequency
20
occurrences
First Seen
November 20, 2025
Last Seen
July 24, 2026

Microsoft Graph API is a tool tracked across 12 threat clusters and 20 intelligence report mentions on ThreatCluster. First observed November 20, 2025; most recent activity July 24, 2026.

Related Threat Clusters

Recent Intelligence Reports

  • Hollowgraph Microsoft 365 — www.group-ib.com · July 24, 2026
  • HollowGraph malware uses Microsoft 365 calendar for command and control — Feeds.Feedburner · July 20, 2026
  • New HollowGraph malware uses Microsoft Graph for stealthy C2 comms — Bleepingcomputer · July 20, 2026
  • Hackers Are Turning Microsoft 365 Calendar Invites Into Secret Malware Command Channels — Cybersecuritynews · July 20, 2026
  • Microsoft 365 calendars become spy drop boxes in HOLLOWGRAPH campaign — Theregister · July 20, 2026
  • New HollowGraph Malware Hijacks Microsoft 365 Calendars for Covert C2 Communications — Infosecurity-Magazine · July 20, 2026
  • Microsoft extends Windows Server 2022 hotpatching until October 2027 — Bleepingcomputer · June 29, 2026
  • Webworm: New burrowing techniques — Welivesecurity · May 20, 2026

CVSS v3.1 Breakdown