31205217676?profile=RESIZE_400xA novel espionage implant, called HollowGraph, is hijacking Microsoft 365 calendars to establish a covert command and control (C2) channel.  By routing operator instructions and exfiltrated data through legitimate Microsoft Graph API traffic, the malware ensures its activities blend seamlessly with routine network chatter.[1]

The .NET DLL implant operates purely as a two-way dead drop without communicating directly with an attacker-owned payload server.  To receive tasking, HollowGraph queries the compromised user’s calendar for an event planted far into the future, in this case, dated for 13 May 2050.  Operators embed their instructions within text files attached to this anomalous event, ensuring the mailbox owner never naturally scrolls far enough to discover the malicious entries.

For data exfiltration, the malware executes the reverse process.  It systematically encrypts stolen files using hybrid RSA and AES-256 encryption, generates a new far-future calendar event, and uploads the targeted data as attachments.  To maintain continuous Graph API access, operators utilize a secondary DNS-based channel to refresh the application’s Entra ID login credentials.  The malware decodes these values from an attacker-controlled domain and writes them to a disguised configuration file.

Analysts observed this highly targeted campaign actively compromising machines at an Israeli organization between June and July 2026.  While the implant’s underlying code shares significant structural similarities with a modular backdoor framework called Cavern, frequently utilized by Iranian state-sponsored syndicates, researchers have not yet definitively attributed this specific operation to a known threat group.

HollowGraph buries its C2 in M365 calendar events dated 2050 – no attacker server ever touched. https://t.co/yJo4fpw0X9 #ThreatIntel #HollowGraph #Cavern #Cav3rn pic.twitter.com/kaABaAYZg0

— ThreadLinqs (@threadlinqs) July 22, 2026

Since HollowGraph relies entirely on compromised account identities and legitimate application permissions rather than software vulnerabilities, standard patching remains ineffective. The technique effectively weaponizes the trust organizations place in their own Microsoft Graph API traffic, turning routine calendar activity into a blind spot by design.

This article is shared at no charge for educational and informational purposes only.

Red Sky Alliance is a Cyber Threat Analysis and Intelligence Service organization.  We provide indicators of compromise information (CTI) via a notification/Tier I analysis service (RedXray) or an analysis service (CTAC).  For questions, comments or assistance, please contact the office directly at 1-844-492-7225, or feedback@redskyalliance.com    

Weekly Cyber Intelligence Briefings:

Weekly Cyber Intelligence Briefings:

REDSHORTS - Weekly Cyber Intelligence Briefings

https://attendee.gotowebinar.com/register/7855487668891299929

[1] https://www.sentinelone.com/blog/the-good-the-bad-and-the-ugly-in-cybersecurity-week-30-8/

E-mail me when people leave their comments –

You need to be a member of Red Sky Alliance to add comments!