Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

HOLLOWGRAPH: Turning Microsoft 365 Calendars into Covert Command-and-Control Channels

0
Medium
Published: 07/20/2026 (07/20/2026, 19:44:29 UTC)
Source: AlienVault OTX General

Description

HOLLOWGRAPH is a sophisticated espionage malware campaign that abuses the Microsoft Graph API to convert compromised Microsoft 365 calendars into covert command-and-control channels. The malware creates calendar events dated to 2050 with encrypted attachments to exfiltrate data and receive commands. It also uses a secondary DNS tunneling channel via IPv6 AAAA records to refresh Microsoft Entra ID credentials for authentication. Communications are secured with hybrid RSA and AES-256-GCM encryption using separate key pairs for inbound and outbound traffic. Twelve infected systems have been identified, mainly targeting Israeli entities, with three actively communicating with attackers. The operation is attributed to the LYCEUM adversary and demonstrates high technical sophistication and focused espionage since at least June 2026.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/21/2026, 10:46:34 UTC

Technical Analysis

This malware campaign leverages Microsoft Graph API abuse to transform Microsoft 365 calendars into covert C2 infrastructure by creating future-dated calendar events containing encrypted attachments for data exfiltration and command reception. It employs a secondary DNS tunneling channel using IPv6 AAAA records to refresh authentication credentials (Microsoft Entra ID). Communications are protected by hybrid RSA and AES-256-GCM encryption with distinct key pairs for inbound and outbound channels. The campaign targets primarily Israeli entities, with twelve infected hosts identified and three actively communicating. The adversary LYCEUM is suspected, indicating a well-resourced espionage operation with disciplined targeting and advanced technical methods.

Potential Impact

The malware enables attackers to covertly exfiltrate sensitive data and issue commands through Microsoft 365 calendar events, bypassing traditional network monitoring. The use of encrypted attachments and DNS tunneling for credential refresh enhances stealth and persistence. This compromises confidentiality and potentially integrity of targeted systems. The focused targeting of Israeli entities suggests espionage motives. No widespread exploitation or known public exploits have been reported.

Mitigation Recommendations

Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Organizations should monitor for suspicious calendar events, especially those dated far in the future with encrypted attachments, and investigate unusual DNS AAAA record queries. Review and restrict Microsoft Graph API permissions to the minimum necessary. Employ anomaly detection for calendar and DNS activity. Follow updates from Microsoft and security vendors for official fixes or mitigations.

Affected Countries

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://www.group-ib.com/blog/hollowgraph-microsoft-365/"]
Adversary
LYCEUM
Pulse Id
6a5e7a9d5abc92aab562f131
Threat Score
null

Indicators of Compromise

Hash

ValueDescriptionCopy
hash315bdba98c6fe863d39f6afccc727e17d5aea63bf21259444fa988cae56d61c1
hash1573e125197ec77d8e9930c611ba2802ee59e19629396b5e99b426b46c53bd25
hash75e51774b8f79e5f256eaae639635f911b3e744d4774fd6068dd980255621509
hashb3d0f6e4e3be395fd7cf9e8101c89963d77216578cbb117a6ac9bc3564485eff
hashf3f3006f8304788251b153d53b305322b8acab0c66ec816b8d9f101bcc851da3

Domain

ValueDescriptionCopy
domaincloudlanecdn.com
domainp.cloudlanecdn.com
domainq.cloudlanecdn.com

Threat ID: 6a5f49772a4a8d5989f62c3c

Added to database: 07/21/2026, 10:27:03 UTC

Last enriched: 07/21/2026, 10:46:34 UTC

Last updated: 07/21/2026, 14:55:47 UTC

Views: 32

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses