HollowGraph Windows malware uses Microsoft 365 calendars for covert C2
Malware Activity
Summary
Hide ▲
Show ▼
HollowGraph is a Windows malware activity that abuses a compromised Microsoft 365 calendar and Microsoft Graph API as covert C2, hiding tasking in far-future 2050-05-13 events and moving encrypted stolen files as attachments. Group-IB said the implant uses DNS tunnelling to refresh Entra ID (Azure AD) client credentials, including values written to logAzure.txt and delivered via cloudlanecdn[.]com. The activity was found on at least 12 systems, with three observed actively communicating during June 3, 2026 to July 9, 2026, and the compromised mailbox belonged to an Israeli organization. Group-IB linked the code to Cavern with high confidence, while stopping short of high-confidence attribution to a known threat actor; the targeting and traffic pattern point to a focused espionage operation.
Related Happenings
HollowGraph Microsoft Graph API calendar C2 campaign targeting Israeli entities
Campaign
H score22
First: 20.07.2026 15:30
Last: 20.07.2026 15:30
Sources 1
How related:
Group-IB, which named the malware HollowGraph, says the approach moves tasking and stolen data through legitimate Microsoft Graph API traffic, so the activity looks like ordinary Microsoft 365 chatter and network controls keyed to attacker-owned destinations have nothing to flag.
About this happening:
HollowGraph is a Windows espionage campaign that abuses a compromised Microsoft 365 calendar and Microsoft Graph API as a covert two-way C2 channel. Group-IB s...
HollowGraph Microsoft Graph API calendar C2 campaign targeting Israeli entities
CampaignHow related: Group-IB, which named the malware HollowGraph, says the approach moves tasking and stolen data through legitimate Microsoft Graph API traffic, so the activity looks like ordinary Microsoft 365 chatter and network controls keyed to attacker-owned destinations have nothing to flag.
About this happening: HollowGraph is a Windows espionage campaign that abuses a compromised Microsoft 365 calendar and Microsoft Graph API as a covert two-way C2 channel. Group-IB s...
ACR Stealer enterprise infostealer surge
Malware Activity
H score29
First: 18.07.2026 17:17
Last: 18.07.2026 17:17
Sources 1
About this happening:
ACR Stealer attacks surged against enterprise customers, putting browser-stored passwords, authentication tokens, cookies, and sensitive documents at risk....
ACR Stealer enterprise infostealer surge
Malware ActivityAbout this happening: ACR Stealer attacks surged against enterprise customers, putting browser-stored passwords, authentication tokens, cookies, and sensitive documents at risk....
ACR Stealer browser credential and document theft activity
Malware Activity
H score29
First: 17.07.2026 11:56
Last: 17.07.2026 11:56
Sources 1
About this happening:
ACR Stealer is driving a surge of browser credential and document theft against enterprise customers. Microsoft said activity climbed from late April to mid-June...
ACR Stealer browser credential and document theft activity
Malware ActivityAbout this happening: ACR Stealer is driving a surge of browser credential and document theft against enterprise customers. Microsoft said activity climbed from late April to mid-June...
GigaWiper / BLUERABBIT destructive Windows backdoor activity
Malware Activity
H score31
First: 09.07.2026 21:08
Last: 09.07.2026 21:08
Sources 1
About this happening:
The GigaWiper / BLUERABBIT malware activity now combines disk wiping, fake ransomware, and spyware backdoor functions on Windows, increasing the chance that on...
GigaWiper / BLUERABBIT destructive Windows backdoor activity
Malware ActivityAbout this happening: The GigaWiper / BLUERABBIT malware activity now combines disk wiping, fake ransomware, and spyware backdoor functions on Windows, increasing the chance that on...
GodDamn ransomware PoisonX BYOVD activity
Malware Activity
H score14
First: 09.07.2026 13:43
Last: 09.07.2026 13:43
Sources 1
About this happening:
GodDamn ransomware, part of the Hyadina family, has evolved into a Windows intrusion chain that uses AnyDesk, credential theft, and the PoisonX kernel driver t...
GodDamn ransomware PoisonX BYOVD activity
Malware ActivityAbout this happening: GodDamn ransomware, part of the Hyadina family, has evolved into a Windows intrusion chain that uses AnyDesk, credential theft, and the PoisonX kernel driver t...
Timeline
-
20.07.2026 15:30 2 articles · 14h ago
HollowGraph uses a compromised Microsoft 365 calendar for victim-attacker communication
Detection Ioc UpdateHollowGraph malware is observed exchanging victim-attacker communication through a compromised Microsoft 365 calendar tied to an Israeli organization, showing the Microsoft Graph API command-and-control channel was active by June 3, 2026.
Show sources
- New HollowGraph Malware Hijacks Microsoft 365 Calendars for Covert C2 Communications — www.infosecurity-magazine.com — 20.07.2026 15:30
- HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050 — thehackernews.com — 20.07.2026 17:33
-
20.07.2026 15:30 3 articles · 14h ago
Group-IB attributes HollowGraph to the Cavern backdoor framework
Initial DisclosureGroup-IB dubbed the Windows malware HollowGraph and attributed it with high confidence to the Cavern backdoor framework, describing a highly targeted campaign against Israeli entities that abuses Microsoft Graph API and Microsoft 365 calendar operations for covert C2. The researchers also recommended hunting for HollowGraph indicators and monitoring Microsoft Graph API activity and Microsoft 365 mailbox audit logs for anomalous calendar operations.
Show sources
- New HollowGraph Malware Hijacks Microsoft 365 Calendars for Covert C2 Communications — www.infosecurity-magazine.com — 20.07.2026 15:30
- New HollowGraph Malware Hijacks Microsoft 365 Calendars for Covert C2 Communications — www.infosecurity-magazine.com — 20.07.2026 15:30
- New HollowGraph malware uses Microsoft Graph for stealthy C2 comms — www.bleepingcomputer.com — 20.07.2026 20:43