Researchers at Group-IB have identified a new espionage implant called HollowGraph that uses hijacked Microsoft 365 calendar events set to the year 2050 to exfiltrate stolen data undetected.
Key Points
- HollowGraph is a .NET DLL malware that uses the Microsoft Graph API to treat compromised mailboxes as two-way dead drops for command-and-control.
- The malware hides instructions and stolen files as encrypted attachments within calendar events dated May 13, 2050, to avoid user discovery.
- A secondary communication channel uses DNS queries to the domain cloudlanecdn[.]com to refresh Entra ID credentials and maintain persistent access.
- Group-IB identified the malware on at least 12 machines, with active traffic observed between June 3 and July 9, 2026.
- The implant shares technical similarities with the Cavern backdoor framework, which has been linked to Iranian state-sponsored threat actors.