Security researchers at Group-IB have discovered HollowGraph, a new espionage implant that weaponizes Microsoft 365 calendars to hide command-and-control communications and exfiltrate stolen data. The malware abuses the legitimate Microsoft Graph API to route operator instructions and stolen files through calendar events artificially dated to the year 2050.
This approach provides operational concealment by masking malicious traffic as normal Microsoft 365 activity. Calendar events containing attacker commands and exfiltrated data blend into legitimate enterprise communications, complicating detection by network monitoring tools and security analysts. The use of future dates further obscures the malicious events from typical calendar review workflows.
The technique represents a shift in how threat actors leverage cloud platforms. Rather than establishing external command servers vulnerable to takedown or blocking, HollowGraph operators use a compromised Microsoft 365 tenant or account as their operational infrastructure. Attackers create calendar entries with stolen data as attachments, retrievable by infected endpoints whenever the operator needs to exfiltrate information. Similarly, infected systems poll the calendar for events containing tasking instructions, receiving commands through what appears to be benign calendar activity.
Organizations face difficulty detecting this attack pattern through traditional means. Endpoint detection and response tools and network sensors may not flag legitimate Microsoft Graph API calls to the calendar service. Log analysis becomes critical but time-consuming. Most security teams do not routinely audit calendar event attachments or flag events with suspicious future dates.
The discovery underscores how threat actors increasingly move away from traditional infrastructure toward residing within cloud services where they operate under cover of legitimate traffic. Defenders must now treat cloud collaboration platforms as potential persistence mechanisms and command channels rather than benign productivity tools.
Organizations should implement strict conditional access policies for Microsoft 365, monitor Graph API activity for suspicious patterns, audit calendar events for attachments and anomalous dates, and enforce multi-
