🟠 High | Source: The Register — Security
A threat campaign dubbed HOLLOWGRAPH is abusing Microsoft 365 calendar invitations to deliver and relay malware commands, with attackers embedding instructions inside appointments dated as far ahead as 2050 to evade detection. The malware uses Microsoft’s own cloud infrastructure as its command-and-control channel, making malicious traffic extremely difficult to distinguish from legitimate Microsoft 365 communications. This living-off-the-land approach significantly reduces the effectiveness of traditional network-based detection controls.
Security Architect’s Take: Review Microsoft 365 audit logs and Defender for Cloud Apps policies for anomalous calendar API activity, particularly calendar items with far-future dates or unusual creation patterns from non-interactive service principals. Consider implementing Conditional Access policies and Microsoft Graph API monitoring to flag atypical programmatic access to calendar endpoints.
Original advisory: Microsoft 365 calendars become spy drop boxes in HOLLOWGRAPH campaign