HollowGraph malware uses Microsoft 365 calendars as command-and-control channel
Attackers now exploit legitimate calendar features in compromised Microsoft 365 accounts to hide malicious communications within everyday business activity.
Calendar Feature Weaponized
Security researchers have identified a new malware component called HollowGraph that leverages the calendar feature in compromised Microsoft 365 mailboxes as a covert command-and-control channel. The technique allows attackers to receive commands and exfiltrate stolen data through what appears to be routine calendar activity.
This approach differs from traditional espionage campaigns that exploit Microsoft 365 infrastructure. Rather than sending visible emails or messages, the malware embeds commands and data within calendar entries, making detection significantly more difficult for security teams monitoring network traffic.
Detection Challenges
The use of Microsoft Graph API and legitimate calendar functionality makes HollowGraph particularly stealthy. Calendar synchronization is expected behavior in enterprise environments, allowing malicious traffic to blend with normal business operations.
Organizations relying on Microsoft 365 for collaboration face additional complexity in identifying compromised accounts when attackers leverage built-in features rather than introducing external tooling or unusual network connections.
Broader Pattern of Living-Off-the-Land
HollowGraph represents a continuing trend of attackers using legitimate cloud services and built-in platform features to evade detection. This "living-off-the-land" approach reduces the need for custom infrastructure and exploits the trust organizations place in sanctioned software.
The discovery follows previous reports of espionage campaigns abusing Microsoft 365 calendars, suggesting that cloud collaboration platforms remain attractive targets for sophisticated threat actors seeking persistent access to corporate environments.