HOLLOWGRAPH: Turning Microsoft 365 Calendars into Covert Command-and-Control Channels


The Group-IB Threat Intelligence team has identified HOLLOWGRAPH, a new malware sample that we attribute, with high confidence, to the Cavern backdoor framework. This malware is one component of a larger toolkit, and it uses the Microsoft Graph API through a compromised Microsoft 365 account observed in Israel to communicate with its operators — a technique that helps conceal command-and-control traffic within legitimate Microsoft 365 communications.

The malware supports just two commands, get and send, and executes both  exclusively through trusted Microsoft cloud infrastructure. Using the Microsoft Graph API, it treats the compromised mailbox’s calendar as a two-way dead-drop: operators plant tasking as calendar events, and the implant exfiltrates stolen files by creating its own events with encrypted data attached. To avoid catching the mailbox owner’s attention, every event is dated far into the future — 13 May 2050 — with payloads attached as files to the event.

Read more…
Source:  Group-IB


Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox


Related:

  • UAE: Up to 100 people arrested by police for filming drone or missile strikes

    March 14, 2026

    Up to 100 people have been arrested by police in the UAE for filming drone or missile strikes, it emerged this morning. Abu Dhabi Police alone have arrested 45 people of multiple nationalities for filming various locations amid current ongoing events and posting clips on social media. In neighbouring Dubai, at least 21 people, including a ...

  • Google patches two Chrome zero-days under active attack

    March 13, 2026

    Update March 16, 2026 Earlier this week, Google incorrectly reported that an actively exploited vulnerability in Chrome had been fixed, and has now announced it will roll out a new update to protect users against the vulnerability tracked as CVE-2026-3909. Original content: Google has released an out-of-band security update for Chrome desktop that patches two high‑severity ...

  • Swedish government IT system hacked

    March 13, 2026

    A large amount of sensitive information allegedly coming from a Swedish government IT system has been posted on the darknet, according to Dagens Nyheter and Expressen. DN writes that the newspaper has taken note of the leak and that it appears to contain the source code for a digital identity management system used by several authorities. ...

  • Poland investigates Iran links behind cyberattack on nuclear facility

    March 12, 2026

    Poland is looking into whether an attempted cyberattack on a nuclear research facility was carried out by Iran, the government said on Thursday. The country’s digital minister Krzysztof Gawkowski said in an emailed statement that Poland had “identified an attempted cyberattack on the servers of the National Centre for Nuclear Research,” which authorities had thwarted. He ...

  • Telus probes cybersecurity incident that ‘ShinyHunters’ group claims responsibility for

    March 12, 2026

    Canadian telecommunications and business services firm Telus is investigating a cybersecurity incident involving unauthorized access to some ‌of its systems, a company spokesperson said on Thursday. The ShinyHunters hacking group told Reuters in a message it stole at least 700 terabytes ​of data from Telus. All business ​operations within the company “remain fully operational, and there ...

  • CISA warns max-severity n8n bug is being exploited in the wild

    March 12, 2026

    The US Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that hackers are exploiting a max-severity remote code execution (RCE) vulnerability in workflow automation platform n8n. CISA urged all federal civilian executive branch (FCEB) agencies to patch CVE-2025-68613 at once because it carries a near-perfect 9.9 vulnerability score. The bug was first disclosed in December, and ...