Security · 13h ago
HollowGraph malware uses Microsoft 365 calendars as command channels
A new campaign called HollowGraph hides malicious commands in Microsoft 365 calendar appointments set for the year 2050. The malware uses Microsoft's own cloud infrastructure to communicate with attackers, making detection difficult. Researchers warn that the technique exploits trusted services to evade security tools.
Meridian48 take
The attack is a clever abuse of trust in cloud services, but its reliance on future-dated appointments may limit stealth over time.
Read the full reporting
Microsoft 365 calendars become spy drop boxes in HOLLOWGRAPH campaign →
The Register
microsoft-365malware