A compromised Microsoft 365 mailbox can do more than hide traffic. It can hold the control channel itself, so cleaning up email or watching outbound connections misses where the operator is actually living inside the tenant.
Group-IB now ties HollowGraph to Cavern Manticore and says the malware uses Microsoft Graph calendar activity as a two-way dead drop. Operators plant tasking as future-dated events, and the implant sends data back by creating its own events with encrypted attachments; Group-IB also found 12 victims and three systems still communicating with attacker infrastructure.
That makes mailbox abuse the persistence point, not just the delivery path. As long as the mailbox and its Graph access survive, the attacker can keep issuing commands and moving data through normal-looking calendar traffic inside Microsoft 365.