Threats & Adversaries · APT / Espionage
Microsoft 365 Calendars Become a Durable C2 Store A compromised Microsoft 365 mailbox can do more than hide traffic. It can hold the control channel itself, so cleaning up email or watching outbound connections misses where the operator is actually living inside the tenant.
Group-IB now ties HollowGraph to Cavern Manticore and says the malware uses Microsoft Graph calendar activity as a two-way dead drop. Operators plant tasking as future-dated events, and the implant sends data back by creating its own events with encrypted attachments; Group-IB also found 12 victims and three systems still communicating with attacker infrastructure.
That makes mailbox abuse the persistence point, not just the delivery path. As long as the mailbox and its Graph access survive, the attacker can keep issuing commands and moving data through normal-looking calendar traffic inside Microsoft 365.
5 sources · Jul 21
Timeline Sources Jul 21 SecurityWeek
New HollowGraph Malware Abuses Microsoft 365 Calendar for C&C Communication
Part of a larger toolkit, HollowGraph uses a compromised 365 account’s calendar as a two-way dead-drop.
original Jul 20 Help Net Security
HOLLOWGRAPH malware turns Microsoft 365 calendars into an espionage channel - Help Net Security
HOLLOWGRAPH malware hides stolen files and commands inside a Microsoft 365 calendar, using events dated to the year 2050 to dodge detection.
original Jul 20 The Hacker News
HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050
HollowGraph uses Microsoft 365 calendar events dated to 2050 to receive commands and exfiltrate encrypted files through legitimate Graph API traffic.
original Vendor digest: Microsoft
Part of the PlainSec briefing for 2026-07-21
Every edition of this story: Microsoft 365 Calendars Become a Durable C2 Store
More from today
Threats & Adversaries · APT / Espionage
Microsoft 365 Calendars Become a Durable C2 Store A compromised Microsoft 365 mailbox can do more than hide traffic. It can hold the control channel itself, so cleaning up email or watching outbound connections misses where the operator is actually living inside the tenant.
Group-IB now ties HollowGraph to Cavern Manticore and says the malware uses Microsoft Graph calendar activity as a two-way dead drop. Operators plant tasking as future-dated events, and the implant sends data back by creating its own events with encrypted attachments; Group-IB also found 12 victims and three systems still communicating with attacker infrastructure.
That makes mailbox abuse the persistence point, not just the delivery path. As long as the mailbox and its Graph access survive, the attacker can keep issuing commands and moving data through normal-looking calendar traffic inside Microsoft 365.
5 sources · Jul 21
Timeline Sources Jul 21 SecurityWeek
New HollowGraph Malware Abuses Microsoft 365 Calendar for C&C Communication
Part of a larger toolkit, HollowGraph uses a compromised 365 account’s calendar as a two-way dead-drop.
original Jul 20 Help Net Security
HOLLOWGRAPH malware turns Microsoft 365 calendars into an espionage channel - Help Net Security
HOLLOWGRAPH malware hides stolen files and commands inside a Microsoft 365 calendar, using events dated to the year 2050 to dodge detection.
original Jul 20 The Hacker News
HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050
HollowGraph uses Microsoft 365 calendar events dated to 2050 to receive commands and exfiltrate encrypted files through legitimate Graph API traffic.
original Vendor digest: Microsoft
Part of the PlainSec briefing for 2026-07-21
Every edition of this story: Microsoft 365 Calendars Become a Durable C2 Store
More from today