Find notable cyber news and cases, enriched with sources, timelines, and signals.

HollowGraph Microsoft Graph API calendar C2 campaign targeting Israeli entities

Campaign
First reported
Last updated
Happening score
H score 22
3 unique sources, 3 articles

Summary

Hide ▲

HollowGraph is a Windows espionage campaign that abuses a compromised Microsoft 365 calendar and Microsoft Graph API as a covert two-way C2 channel. Group-IB said the implant hides tasking in 2050-05-13 calendar events, exfiltrates encrypted files as attachments, and also uses DNS tunneling to refresh Microsoft Entra ID (Azure AD) credentials from cloudlanecdn[.]com into logAzure.txt. The campaign was observed against Israeli entities, with victim communication seen from June 3, 2026 through July 9, 2026. Group-IB found the implant on at least 12 systems, with three actively communicating during that window, and linked the code to Cavern with high confidence while noting only lower-confidence similarity to Lyceum.

Related Happenings

HollowGraph Windows malware uses Microsoft 365 calendars for covert C2

Malware Activity
H score15 First: 20.07.2026 15:30 Last: 20.07.2026 15:30 Sources 1

How related: The implant is a .NET DLL that supports just two commands, get and send, and it never reaches out to an attacker-owned server for payloads. Instead, it treats the compromised mailbox's calendar as a two-way dead drop.

About this happening: HollowGraph is a Windows malware activity that abuses a compromised Microsoft 365 calendar and Microsoft Graph API as covert C2, hiding tasking in far-future *...

Hotel and hospitality photo-ZIP phishing campaign

Campaign
H score40 First: 26.06.2026 12:27 Last: 26.06.2026 12:27 Sources 1

About this happening: An active phishing campaign is targeting hotel and hospitality organizations across Europe and Asia, increasing the risk of front-desk machine compromise and durab...

Earth Lusca Operation FishMedley espionage campaign

Campaign
H score38 First: 16.06.2026 12:44 Last: 16.06.2026 12:44 Sources 1

About this happening: A multi-country espionage campaign tied to Earth Lusca / FishMonger is now linked to Operation FishMedley, a January–October 2022 effort that reached seven organ...

Operation Dragon Weave cyber-espionage campaign

Campaign
H score37 First: 01.06.2026 14:54 Last: 01.06.2026 14:54 Sources 1

About this happening: The Operation Dragon Weave campaign is actively targeting officials and citizens in the Czech Republic and Taiwan with spear-phishing ZIP attachments. The infection ch...

AI chatbot cryptojacking campaign targeting high-performance GPU users

Campaign
H score51 First: 27.05.2026 10:45 Last: 27.05.2026 10:45 Sources 1

About this happening: Microsoft warned of an active cryptojacking campaign that uses SEO poisoning and, in some cases, AI chatbot recommendations to steer users to malicious ZIP downloa...

Timeline

  1. 20.07.2026 15:30 1 articles · 14h ago

    Earliest observed victim-attacker communication in the HollowGraph campaign

    Campaign Scope Update

    Earliest observed communication between a victim and attacker occurred in the HollowGraph campaign affecting Israeli entities, marking the first monitored interaction tied to a compromised Microsoft 365 calendar and Microsoft Graph API covert C2 setup.

    Show sources
  2. 20.07.2026 15:30 1 articles · 14h ago

    Latest observed victim-attacker communication in the HollowGraph campaign

    Campaign Scope Update

    The latest observed example of HollowGraph victim-attacker communication was identified, showing the targeted operation continued into July against Israeli entities and remained consistent with covert calendar-based tasking.

    Show sources
  3. 20.07.2026 15:30 4 articles · 14h ago

    HollowGraph malware is tied to the Cavern framework

    Initial Disclosure

    HollowGraph is a Windows malware sample that abuses Microsoft Graph API to transform a compromised Microsoft 365 calendar into a covert two-way C2 channel, with high-confidence attribution to the Cavern backdoor framework and technical similarities to Lyceum. The sample uses get and send commands, calendar appointments with encrypted stolen files attached, DNS tunneling to refresh Microsoft Entra ID (Azure AD) credentials, and RSA and AES-256-GCM encryption for Graph communications. Defensive guidance calls for hunting HollowGraph indicators and monitoring Microsoft Graph API activity and Microsoft 365 mailbox audit logs for anomalous calendar operations.

    Show sources