HOLLOWGRAPH malware turns Microsoft 365 calendars into an espionage channel

Researchers have identified a new malware strain called HOLLOWGRAPH that uses Microsoft 365 calendar events to facilitate espionage. The malware, linked to potential Iranian-nexus actors, hides commands and stolen data within future-dated calendar appointments.
Why it matters
It reveals a sophisticated new vector for cyber espionage that exploits common enterprise productivity tools to bypass traditional security monitoring.
HOLLOWGRAPH malware turns Microsoft 365 calendars into an espionage channel Microsoft 365 calendars have become a hiding place for espionage malware, with commands and stolen files stashed inside appointments dated to the year 2050, researchers from Group-IB discovered.
The malware, which Group-IB calls HOLLOWGRAPH, is one component of a bigger toolkit the company links with high confidence to the Cavern backdoor framework, a modular espionage toolkit built from separate plugins that each handle a different task, previously tied to Iran-linked activity.
Group-IB identified 12 infected systems (three actively communicating), all evidence pointing to a narrowly targeted espionage operation against Israeli entities.
The earliest recorded contact between a victim and the attacker dates to June 3, 2026, and the most recent to July 9, 2026, a window showing the malware has been in active use since at least early June.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in