Microsoft 365 calendars exploited as command-and-control infrastructure in espionage campaign

Attackers are weaponizing trusted Microsoft cloud services to evade detection, hiding espionage commands in calendar appointments scheduled decades into the future.

Abstract illustration showing nested geometric forms representing hidden data within calendar infrastructure
AI-generated illustration · Sylvaris

Calendar appointments as covert channels

Security researchers have identified a campaign dubbed HOLLOWGRAPH where threat actors use Microsoft 365 calendar appointments as drop boxes for espionage commands. The attackers schedule appointments far into the future—some set for 2050—to hide malicious payloads within calendar metadata.

The technique exploits the fact that calendar synchronization traffic appears legitimate to security tools. By using Microsoft's own cloud infrastructure for command-and-control communications, the malware blends into normal enterprise activity and avoids triggering traditional network security alerts.

Implications for enterprise security

The campaign demonstrates how attackers increasingly weaponize trusted cloud platforms rather than building custom infrastructure. Organizations relying on perimeter defenses face challenges detecting threats that operate entirely within sanctioned cloud services.

Security teams may need to expand monitoring beyond network boundaries to include behavioral analysis of cloud service usage patterns. Calendar applications, typically considered low-risk productivity tools, now require scrutiny alongside email and file-sharing systems.

sources
more in Security
Upbound breach enabled $13 million in fraudulent Acima leases Stolen customer data was directly weaponized to create fraudulent financial contracts, demonstrating how breach data enables immediate financial crime. Fake job interview delivers malware through Git hooks in take-home coding projects Attackers are weaponizing the technical interview process itself, embedding malicious Git hooks in legitimate-looking coding assignments to compromise developer workstations. South Korea National Diplomatic Academy breach exposes global diplomat data after ten-month intrusion A prolonged breach of diplomatic training infrastructure exposed sensitive personnel data of current and former foreign service officers worldwide, demonstrating the targeting of government educational systems.