Threats · 55 days ago
A compromised Microsoft 365 mailbox can do more than hide traffic. It can hold the control channel itself, so cleaning up email or watching outbound connections misses where the operator is actually living inside the tenant.
Group-IB now ties HollowGraph to Cavern Manticore and says the malware uses Microsoft Graph calendar activity as a two-way dead drop. Operators plant tasking as future-dated events, and the implant sends data back by creating its own events with encrypted attachments; Group-IB also found 12 victims and three systems still communicating with attacker infrastructure.
That makes mailbox abuse the persistence point, not just the delivery path. As long as the mailbox and its Graph access survive, the attacker can keep issuing commands and moving data through normal-looking calendar traffic inside Microsoft 365.
5 sources covering this story
New HollowGraph Malware Abuses Microsoft 365 Calendar for C&C Communication
Part of a larger toolkit, HollowGraph uses a compromised 365 account’s calendar as a two-way dead-drop.
HOLLOWGRAPH malware turns Microsoft 365 calendars into an espionage channel - Help Net Security
HOLLOWGRAPH malware hides stolen files and commands inside a Microsoft 365 calendar, using events dated to the year 2050 to dodge detection.
HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050
HollowGraph uses Microsoft 365 calendar events dated to 2050 to receive commands and exfiltrate encrypted files through legitimate Graph API traffic.
New HollowGraph malware uses Microsoft Graph for stealthy C2 comms
A malicious component dubbed HollowGraph uses the calendar feature in compromised Microsoft 365 mailboxes as a command-and-control channel to receive attacker commands and exfiltrate stolen data.
New HollowGraph Malware Hijacks Microsoft 365 Calendars for Covert C2
Researchers have linked HollowGraph malware to the Cavern framework after discovering its use of Microsoft 365 calendars and Microsoft Graph APIs as a stealthy C2 channel
Part of the PlainSec briefing for 2026-07-22