HollowGraph Microsoft Graph API calendar C2 campaign targeting Israeli entities
Campaign
Summary
Hide ▲
Show ▼
HollowGraph is a Windows espionage campaign that abuses a compromised Microsoft 365 calendar and Microsoft Graph API as a covert two-way C2 channel. Group-IB said the implant hides tasking in 2050-05-13 calendar events, exfiltrates encrypted files as attachments, and also uses DNS tunneling to refresh Microsoft Entra ID (Azure AD) credentials from cloudlanecdn[.]com into logAzure.txt. The campaign was observed against Israeli entities, with victim communication seen from June 3, 2026 through July 9, 2026. Group-IB found the implant on at least 12 systems, with three actively communicating during that window, and linked the code to Cavern with high confidence while noting only lower-confidence similarity to Lyceum.
Related Happenings
HollowGraph Windows malware uses Microsoft 365 calendars for covert C2
Malware Activity
H score15
First: 20.07.2026 15:30
Last: 20.07.2026 15:30
Sources 1
How related:
The implant is a .NET DLL that supports just two commands, get and send, and it never reaches out to an attacker-owned server for payloads. Instead, it treats the compromised mailbox's calendar as a two-way dead drop.
About this happening:
HollowGraph is a Windows malware activity that abuses a compromised Microsoft 365 calendar and Microsoft Graph API as covert C2, hiding tasking in far-future *...
HollowGraph Windows malware uses Microsoft 365 calendars for covert C2
Malware ActivityHow related: The implant is a .NET DLL that supports just two commands, get and send, and it never reaches out to an attacker-owned server for payloads. Instead, it treats the compromised mailbox's calendar as a two-way dead drop.
About this happening: HollowGraph is a Windows malware activity that abuses a compromised Microsoft 365 calendar and Microsoft Graph API as covert C2, hiding tasking in far-future *...
Hotel and hospitality photo-ZIP phishing campaign
Campaign
H score40
First: 26.06.2026 12:27
Last: 26.06.2026 12:27
Sources 1
About this happening:
An active phishing campaign is targeting hotel and hospitality organizations across Europe and Asia, increasing the risk of front-desk machine compromise and durab...
Hotel and hospitality photo-ZIP phishing campaign
CampaignAbout this happening: An active phishing campaign is targeting hotel and hospitality organizations across Europe and Asia, increasing the risk of front-desk machine compromise and durab...
Earth Lusca Operation FishMedley espionage campaign
Campaign
H score38
First: 16.06.2026 12:44
Last: 16.06.2026 12:44
Sources 1
About this happening:
A multi-country espionage campaign tied to Earth Lusca / FishMonger is now linked to Operation FishMedley, a January–October 2022 effort that reached seven organ...
Earth Lusca Operation FishMedley espionage campaign
CampaignAbout this happening: A multi-country espionage campaign tied to Earth Lusca / FishMonger is now linked to Operation FishMedley, a January–October 2022 effort that reached seven organ...
Operation Dragon Weave cyber-espionage campaign
Campaign
H score37
First: 01.06.2026 14:54
Last: 01.06.2026 14:54
Sources 1
About this happening:
The Operation Dragon Weave campaign is actively targeting officials and citizens in the Czech Republic and Taiwan with spear-phishing ZIP attachments. The infection ch...
Operation Dragon Weave cyber-espionage campaign
CampaignAbout this happening: The Operation Dragon Weave campaign is actively targeting officials and citizens in the Czech Republic and Taiwan with spear-phishing ZIP attachments. The infection ch...
AI chatbot cryptojacking campaign targeting high-performance GPU users
Campaign
H score51
First: 27.05.2026 10:45
Last: 27.05.2026 10:45
Sources 1
About this happening:
Microsoft warned of an active cryptojacking campaign that uses SEO poisoning and, in some cases, AI chatbot recommendations to steer users to malicious ZIP downloa...
AI chatbot cryptojacking campaign targeting high-performance GPU users
CampaignAbout this happening: Microsoft warned of an active cryptojacking campaign that uses SEO poisoning and, in some cases, AI chatbot recommendations to steer users to malicious ZIP downloa...
Timeline
-
20.07.2026 15:30 1 articles · 14h ago
Earliest observed victim-attacker communication in the HollowGraph campaign
Campaign Scope UpdateEarliest observed communication between a victim and attacker occurred in the HollowGraph campaign affecting Israeli entities, marking the first monitored interaction tied to a compromised Microsoft 365 calendar and Microsoft Graph API covert C2 setup.
Show sources
- New HollowGraph Malware Hijacks Microsoft 365 Calendars for Covert C2 Communications — www.infosecurity-magazine.com — 20.07.2026 15:30
-
20.07.2026 15:30 1 articles · 14h ago
Latest observed victim-attacker communication in the HollowGraph campaign
Campaign Scope UpdateThe latest observed example of HollowGraph victim-attacker communication was identified, showing the targeted operation continued into July against Israeli entities and remained consistent with covert calendar-based tasking.
Show sources
- New HollowGraph Malware Hijacks Microsoft 365 Calendars for Covert C2 Communications — www.infosecurity-magazine.com — 20.07.2026 15:30
-
20.07.2026 15:30 4 articles · 14h ago
HollowGraph malware is tied to the Cavern framework
Initial DisclosureHollowGraph is a Windows malware sample that abuses Microsoft Graph API to transform a compromised Microsoft 365 calendar into a covert two-way C2 channel, with high-confidence attribution to the Cavern backdoor framework and technical similarities to Lyceum. The sample uses get and send commands, calendar appointments with encrypted stolen files attached, DNS tunneling to refresh Microsoft Entra ID (Azure AD) credentials, and RSA and AES-256-GCM encryption for Graph communications. Defensive guidance calls for hunting HollowGraph indicators and monitoring Microsoft Graph API activity and Microsoft 365 mailbox audit logs for anomalous calendar operations.
Show sources
- New HollowGraph Malware Hijacks Microsoft 365 Calendars for Covert C2 Communications — www.infosecurity-magazine.com — 20.07.2026 15:30
- New HollowGraph Malware Hijacks Microsoft 365 Calendars for Covert C2 Communications — www.infosecurity-magazine.com — 20.07.2026 15:30
- HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050 — thehackernews.com — 20.07.2026 17:33
- New HollowGraph malware uses Microsoft Graph for stealthy C2 comms — www.bleepingcomputer.com — 20.07.2026 20:43