New Malware Turns Microsoft 365 Calendars Into Covert Command-and-Control Channel
Security researchers have identified a new malware strain called HOLLOWGRAPH that uses Microsoft 365 calendar events as a covert command-and-control channel. The malware allows attackers to exfiltrate data and receive instructions by hiding malicious activity within legitimate cloud traffic.
Why it matters
This discovery highlights the evolving sophistication of espionage campaigns that exploit trusted enterprise software to bypass traditional security defenses.
A newly uncovered Windows malware implant is abusing Microsoft 365 calendar events to receive instructions and exfiltrate stolen files, allowing its operators to conceal espionage activity inside legitimate Microsoft cloud traffic.
The malware, named HOLLOWGRAPH by Group-IB , transforms a compromised Microsoft 365 mailbox calendar into a two-way command-and-control channel. Attackers place encrypted instructions inside calendar-event attachments, while infected computers return stolen information by creating additional appointments and uploading encrypted files.
To prevent the malicious events from attracting the mailbox owner’s attention, the attackers schedule them for May 13, 2050—nearly 24 years in the future.
Group-IB said it identified at least 12 systems infected with HOLLOWGRAPH. Three were actively communicating with attacker-controlled infrastructure during the company’s observation period.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in