New HollowGraph Malware Abuses Microsoft 365 Calendar for C&C Communication
HollowGraph is a malware that abuses a compromised Microsoft 365 calendar for command-and-control (C&C) communication by using calendar events as a two-way dead-drop. It attaches encrypted payloads to calendar events dated far in the future to avoid detection. The malware uses Microsoft Graph API and a compromised mailbox, primarily targeting Israeli entities. It also employs DNS tunneling for secondary communication and retains Microsoft Entra ID credentials for authentication. Attribution to an Iranian-linked threat actor is low confidence. The malware has been active since at least June 2026 and is part of a larger toolkit.
AI Analysis
Technical Summary
HollowGraph malware leverages the Microsoft 365 calendar of a compromised account to conduct C&C communication by planting and retrieving encrypted calendar events using the Microsoft Graph API. Operators embed tasking instructions as calendar events, while the malware exfiltrates stolen data by creating its own calendar events with encrypted attachments dated far in the future (e.g., May 2050) to evade detection. It uses hybrid RSA and AES encryption for payload security. The malware also maintains a secondary communication channel via DNS tunneling to refresh its configuration and Azure AD credentials. Group-IB identified 12 victims, mainly in Israel, with active communications observed since June 3, 2026. The malware is linked with low confidence to the Iranian MOIS-associated OilRig subgroup Lyceum. HollowGraph does not contact attacker-controlled servers directly for payload delivery but relies on two commands, 'send' and 'get', to manage calendar events for C&C. Its configuration, including Azure AD tenant and client IDs and RSA keys, is stored locally in a log file.
Potential Impact
HollowGraph enables stealthy command-and-control communication and data exfiltration through legitimate Microsoft 365 calendar events, complicating detection and response. It targets specific entities, primarily in Israel, and uses encrypted payloads and future-dated calendar events to avoid alerting mailbox owners. The malware’s use of legitimate cloud services for C&C reduces the likelihood of network-based detection. The impact is limited to entities with compromised Microsoft 365 accounts and does not indicate widespread opportunistic attacks.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since this malware abuses compromised Microsoft 365 accounts, mitigation should focus on securing accounts with strong authentication methods such as multi-factor authentication (MFA), monitoring for unusual calendar activity, and promptly investigating suspicious calendar events dated far in the future. Review and restrict application permissions related to Microsoft Graph API and Azure AD credentials. Organizations should also monitor DNS tunneling activity as a secondary communication channel. No official patch or fix is indicated for the malware itself, as it exploits legitimate cloud service features.
New HollowGraph Malware Abuses Microsoft 365 Calendar for C&C Communication
Description
HollowGraph is a malware that abuses a compromised Microsoft 365 calendar for command-and-control (C&C) communication by using calendar events as a two-way dead-drop. It attaches encrypted payloads to calendar events dated far in the future to avoid detection. The malware uses Microsoft Graph API and a compromised mailbox, primarily targeting Israeli entities. It also employs DNS tunneling for secondary communication and retains Microsoft Entra ID credentials for authentication. Attribution to an Iranian-linked threat actor is low confidence. The malware has been active since at least June 2026 and is part of a larger toolkit.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
HollowGraph malware leverages the Microsoft 365 calendar of a compromised account to conduct C&C communication by planting and retrieving encrypted calendar events using the Microsoft Graph API. Operators embed tasking instructions as calendar events, while the malware exfiltrates stolen data by creating its own calendar events with encrypted attachments dated far in the future (e.g., May 2050) to evade detection. It uses hybrid RSA and AES encryption for payload security. The malware also maintains a secondary communication channel via DNS tunneling to refresh its configuration and Azure AD credentials. Group-IB identified 12 victims, mainly in Israel, with active communications observed since June 3, 2026. The malware is linked with low confidence to the Iranian MOIS-associated OilRig subgroup Lyceum. HollowGraph does not contact attacker-controlled servers directly for payload delivery but relies on two commands, 'send' and 'get', to manage calendar events for C&C. Its configuration, including Azure AD tenant and client IDs and RSA keys, is stored locally in a log file.
Potential Impact
HollowGraph enables stealthy command-and-control communication and data exfiltration through legitimate Microsoft 365 calendar events, complicating detection and response. It targets specific entities, primarily in Israel, and uses encrypted payloads and future-dated calendar events to avoid alerting mailbox owners. The malware’s use of legitimate cloud services for C&C reduces the likelihood of network-based detection. The impact is limited to entities with compromised Microsoft 365 accounts and does not indicate widespread opportunistic attacks.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since this malware abuses compromised Microsoft 365 accounts, mitigation should focus on securing accounts with strong authentication methods such as multi-factor authentication (MFA), monitoring for unusual calendar activity, and promptly investigating suspicious calendar events dated far in the future. Review and restrict application permissions related to Microsoft Graph API and Azure AD credentials. Organizations should also monitor DNS tunneling activity as a secondary communication channel. No official patch or fix is indicated for the malware itself, as it exploits legitimate cloud service features.
Technical Details
- Article Source
- {"url":"https://www.securityweek.com/new-hollowgraph-malware-abuses-microsoft-365-calendar-for-cc-communication/","fetched":true,"fetchedAt":"2026-07-21T11:56:48.010Z","wordCount":1121}
Threat ID: 6a5f5e802a4a8d598913f5c8
Added to database: 07/21/2026, 11:56:48 UTC
Last enriched: 07/21/2026, 11:56:55 UTC
Last updated: 07/21/2026, 20:47:43 UTC
Views: 10
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.