HOLLOWGRAPH Microsoft 365 calendar C2 and exfiltration
Malware Activity
Summary
Hide ▲
Show ▼
The HOLLOWGRAPH malware now uses Microsoft 365 calendar events and the Microsoft Graph API as a covert channel for command reception and file exfiltration, increasing the risk of hidden activity inside compromised mailboxes. It also uses DNS tunneling to refresh credentials for C2 communication, making the implant harder to disrupt. The module was first detected in the wild on June 7, 2026, and its calendar-based dead-drop can hide tasking behind future-dated events.
Related Happenings
HollowGraph Microsoft Graph API calendar C2 campaign targeting Israeli entities
Campaign
H score22
First: 20.07.2026 15:30
Last: 20.07.2026 15:30
Sources 1
How related:
Two back-to-back follow-up reports from Group-IB and Kaspersky detailed another module dubbed HOLLOWGRAPH that turns Microsoft 365 calendars into covert C2 channels.
About this happening:
HollowGraph is a Windows espionage campaign that abuses a compromised Microsoft 365 calendar and Microsoft Graph API as a covert two-way C2 channel. Group-IB s...
HollowGraph Microsoft Graph API calendar C2 campaign targeting Israeli entities
CampaignHow related: Two back-to-back follow-up reports from Group-IB and Kaspersky detailed another module dubbed HOLLOWGRAPH that turns Microsoft 365 calendars into covert C2 channels.
About this happening: HollowGraph is a Windows espionage campaign that abuses a compromised Microsoft 365 calendar and Microsoft Graph API as a covert two-way C2 channel. Group-IB s...
HollowGraph Windows malware uses Microsoft 365 calendars for covert C2
Malware Activity
H score15
First: 20.07.2026 15:30
Last: 20.07.2026 15:30
Sources 1
How related:
"Using the Microsoft Graph API, it treats the compromised mailbox's calendar as a two-way dead-drop: operators plant tasking as calendar events, and the implant exfiltrates stolen files by creating its own events with encrypted data attached," Group-IB noted.
About this happening:
HollowGraph is a Windows malware activity that abuses a compromised Microsoft 365 calendar and Microsoft Graph API as covert C2, hiding tasking in far-future *...
HollowGraph Windows malware uses Microsoft 365 calendars for covert C2
Malware ActivityHow related: "Using the Microsoft Graph API, it treats the compromised mailbox's calendar as a two-way dead-drop: operators plant tasking as calendar events, and the implant exfiltrates stolen files by creating its own events with encrypted data attached," Group-IB noted.
About this happening: HollowGraph is a Windows malware activity that abuses a compromised Microsoft 365 calendar and Microsoft Graph API as covert C2, hiding tasking in far-future *...
Dental clinic hit by network compromise
Incident
H score12
First: 20.07.2026 12:07
Last: 20.07.2026 12:07
Sources 1
About this happening:
A dental clinic suffered an unauthorized compromise after a threat actor used Google Gemini CLI to run C&C infrastructure that controlled eight computers and r...
Dental clinic hit by network compromise
IncidentAbout this happening: A dental clinic suffered an unauthorized compromise after a threat actor used Google Gemini CLI to run C&C infrastructure that controlled eight computers and r...
GoSerpent malware activity targeting Southeast Asian entities
Malware Activity
H score26
First: 17.07.2026 11:46
Last: 17.07.2026 11:46
Sources 1
About this happening:
GoSerpent is being used in cyber attacks against entities in Southeast Asia, with the activity focused on long-term access, intelligence gathering, and data...
GoSerpent malware activity targeting Southeast Asian entities
Malware ActivityAbout this happening: GoSerpent is being used in cyber attacks against entities in Southeast Asia, with the activity focused on long-term access, intelligence gathering, and data...
DoNot Team Bangladesh military and defence espionage campaign
Campaign
H score38
First: 17.07.2026 11:46
Last: 17.07.2026 11:46
Sources 1
About this happening:
A DoNot Team espionage campaign targeted Bangladesh's military and defence establishments, using spear-phishing RTF files to deliver a DLL implant and establish ...
DoNot Team Bangladesh military and defence espionage campaign
CampaignAbout this happening: A DoNot Team espionage campaign targeted Bangladesh's military and defence establishments, using spear-phishing RTF files to deliver a DLL implant and establish ...
Timeline
-
17.08.2026 20:41 1 articles · 4h ago
HOLLOWGRAPH is first detected in the wild
Detection Ioc UpdateHOLLOWGRAPH was first detected in the wild on June 7, 2026, establishing the earliest confirmed sighting of the .NET NativeAOT-compiled DLL used for Microsoft 365 calendar-based command-and-control and file exfiltration.
Show sources
- Cavern C2 Uses DNS and Google Apps Script to Blend Into Legitimate Traffic — thehackernews.com — 17.08.2026 20:41
-
17.08.2026 20:41 2 articles · 4h ago
Researchers detail HOLLOWGRAPH calendar-based command-and-control
Initial DisclosureHOLLOWGRAPH turns Microsoft 365 calendars into a covert command-and-control channel by abusing the Microsoft Graph API to receive commands and exfiltrate files, while DNS tunneling refreshes Microsoft Entra ID credentials used to authenticate to the Graph API. Operators hide tasking in future-dated calendar events, including events set to 13 May 2050, with payloads attached as files.
Show sources
- Cavern C2 Uses DNS and Google Apps Script to Blend Into Legitimate Traffic — thehackernews.com — 17.08.2026 20:41
- Cavern C2 Uses DNS and Google Apps Script to Blend Into Legitimate Traffic — thehackernews.com — 17.08.2026 20:41