HollowGraph Windows malware uses Microsoft 365 calendars for covert C2
Malware Activity
Updated: 20.07.2026 15:30
· First: 20.07.2026 15:30
· 📰 3 src / 3 articles
· H score: 15
HollowGraph is a Windows malware activity that abuses a compromised Microsoft 365 calendar and Microsoft Graph API as covert C2, hiding tasking in far-future 2050-05-13 events and moving encrypted stolen files as attachments. Group-IB said the implant uses DNS tunnelling to refresh Entra ID (Azure AD) client credentials, including values written to logAzure.txt and delivered via cloudlanecdn[.]com. The activity was found on at least 12 systems, with three observed actively communicating during June 3, 2026 to July 9, 2026, and the compromised mailbox belonged to an Israeli organization. Group-IB linked the code to Cavern with high confidence, while stopping short of high-confidence attribution to a known threat actor; the targeting and traffic pattern point to a focused espionage operation.