TUESDAY, JULY 21, 2026 48° E  /  GLOBAL TECH · SUMMARISED SUBSCRIBE
AI, business, devices, policy — global tech, summarised every 30 minutes.
Security · 10h ago

HollowGraph Malware Hides C2 in Microsoft 365 Calendar Events

By Meridian48 News Desk · Summarised from DEV Community ·

Group-IB discovered HollowGraph, a .NET DLL that uses Microsoft 365 calendar events as a dead-drop C2 channel, encrypting commands in future-dated entries. The malware has infected at least 12 systems, targeting Israeli organizations via the Microsoft Graph API. It also uses DNS tunneling to refresh credentials, blending into normal cloud traffic.

Meridian48 take
The technique is clever but not novel; the real story is how attackers weaponize trusted cloud APIs to bypass traditional network defenses.
Read the full reporting
HollowGraph Malware Uses Microsoft 365 Calendar Events as Dead-Drop C2 Channel →
DEV Community
hollowgraph-malwaremicrosoft-365-security
More security briefs
Go deeper on security
AllAIStartupsBusinessDevicesPolicySecurityDev ToolsPakistan