🟠 High  |  Source: The Hacker News


HollowGraph is an espionage implant that abuses Microsoft 365 calendar events — dated to 2050 to avoid attention — to receive operator commands and exfiltrate stolen files as attachments. It communicates exclusively via the legitimate Microsoft Graph API, making malicious traffic extremely difficult to distinguish from normal Microsoft 365 activity. The technique was uncovered by Group-IB and represents a sophisticated living-off-the-land approach that sidesteps many traditional network-based detections.

Security Architect’s Take: Review Microsoft Graph API activity in your SIEM for anomalous calendar event creation, particularly events with far-future dates or unusual attachment patterns on service or shared accounts. Consider implementing Conditional Access policies to restrict which applications and identities can interact with the Graph API, and enable Microsoft 365 Unified Audit Logging to capture calendar and attachment events for threat hunting.

Original advisory: HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050