HollowGraph malware uses Microsoft 365 calendars as command-and-control channel

Attackers now exploit legitimate calendar features in compromised Microsoft 365 accounts to hide malicious communications within everyday business activity.

Abstract illustration showing calendar grids with hidden data pathways
AI-generated illustration · Sylvaris

Calendar Feature Weaponized

Security researchers have identified a new malware component called HollowGraph that leverages the calendar feature in compromised Microsoft 365 mailboxes as a covert command-and-control channel. The technique allows attackers to receive commands and exfiltrate stolen data through what appears to be routine calendar activity.

This approach differs from traditional espionage campaigns that exploit Microsoft 365 infrastructure. Rather than sending visible emails or messages, the malware embeds commands and data within calendar entries, making detection significantly more difficult for security teams monitoring network traffic.

Detection Challenges

The use of Microsoft Graph API and legitimate calendar functionality makes HollowGraph particularly stealthy. Calendar synchronization is expected behavior in enterprise environments, allowing malicious traffic to blend with normal business operations.

Organizations relying on Microsoft 365 for collaboration face additional complexity in identifying compromised accounts when attackers leverage built-in features rather than introducing external tooling or unusual network connections.

Broader Pattern of Living-Off-the-Land

HollowGraph represents a continuing trend of attackers using legitimate cloud services and built-in platform features to evade detection. This "living-off-the-land" approach reduces the need for custom infrastructure and exploits the trust organizations place in sanctioned software.

The discovery follows previous reports of espionage campaigns abusing Microsoft 365 calendars, suggesting that cloud collaboration platforms remain attractive targets for sophisticated threat actors seeking persistent access to corporate environments.

sources
more in Security
Upbound breach enabled $13 million in fraudulent Acima leases Stolen customer data was directly weaponized to create fraudulent financial contracts, demonstrating how breach data enables immediate financial crime. Fake job interview delivers malware through Git hooks in take-home coding projects Attackers are weaponizing the technical interview process itself, embedding malicious Git hooks in legitimate-looking coding assignments to compromise developer workstations. South Korea National Diplomatic Academy breach exposes global diplomat data after ten-month intrusion A prolonged breach of diplomatic training infrastructure exposed sensitive personnel data of current and former foreign service officers worldwide, demonstrating the targeting of government educational systems.