AUTO-UPDATED

HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050

Researchers at Group-IB have identified a new espionage implant called HollowGraph that uses hijacked Microsoft 365 calendar events set to the year 2050 to exfiltrate stolen data undetected.

Key Points

  • HollowGraph is a .NET DLL malware that uses the Microsoft Graph API to treat compromised mailboxes as two-way dead drops for command-and-control.
  • The malware hides instructions and stolen files as encrypted attachments within calendar events dated May 13, 2050, to avoid user discovery.
  • A secondary communication channel uses DNS queries to the domain cloudlanecdn[.]com to refresh Entra ID credentials and maintain persistent access.
  • Group-IB identified the malware on at least 12 machines, with active traffic observed between June 3 and July 9, 2026.
  • The implant shares technical similarities with the Cavern backdoor framework, which has been linked to Iranian state-sponsored threat actors.

Why it Matters

This campaign highlights a growing trend of attackers leveraging legitimate cloud service functionality to bypass traditional network security controls. Because the malware exploits standard API traffic rather than software vulnerabilities, organizations must prioritize identity monitoring and strict auditing of application permissions to detect unauthorized mailbox activity.
Internet Published by info@thehackernews.com (The Hacker News)
Read original