Malware Hijacks Microsoft 365 Calendars for Covert Command-and-Control
Security researchers at Group-IB have discovered a Windows malware strain called HOLLOWGRAPH that uses Microsoft 365 calendars as covert channels for receiving commands and stealing files from targeted organizations. The malware abuses the Microsoft Graph API and a compromised account's calendar to conceal command-and-control activity within legitimate cloud communications.
HOLLOWGRAPH uploads stolen files as attachments to separate events, which are scheduled for May 13, 2050, far outside the mailbox owner's normal calendar view. This approach allows the malware to communicate through Microsoft infrastructure without connecting directly to an attacker-controlled server for its primary command channel.
The researchers linked HOLLOWGRAPH with high confidence to the Cavern backdoor framework based on similarities in command syntax and architecture. The firm found at least 12 infected systems, though only three were actively communicating with the attacker during the observation period.