Security · 14h ago
HollowGraph Malware Hijacks Microsoft 365 Calendar for Stealthy C2
A new espionage implant called HollowGraph uses hijacked Microsoft 365 calendars as a command channel, hiding instructions and stolen files in calendar events dated to 2050. Group-IB researchers found the malware routes tasking and exfiltrated data through legitimate Microsoft Graph API traffic, making it appear normal. The approach allows attackers to blend in with regular Office 365 activity, evading detection.
Meridian48 take
The technique is clever but not novel—abusing trusted cloud services for C2 is a growing trend that defenders must account for in their monitoring.
Read the full reporting
HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050 →
The Hacker News
malwaremicrosoft-365