Find notable cyber news and cases, enriched with sources, timelines, and signals.

HOLLOWGRAPH Microsoft 365 calendar C2 and exfiltration

Malware Activity
First reported
Last updated
Happening score
H score 22
1 unique sources, 1 articles

Summary

Hide ▲

The HOLLOWGRAPH malware now uses Microsoft 365 calendar events and the Microsoft Graph API as a covert channel for command reception and file exfiltration, increasing the risk of hidden activity inside compromised mailboxes. It also uses DNS tunneling to refresh credentials for C2 communication, making the implant harder to disrupt. The module was first detected in the wild on June 7, 2026, and its calendar-based dead-drop can hide tasking behind future-dated events.

Related Happenings

HollowGraph Microsoft Graph API calendar C2 campaign targeting Israeli entities

Campaign
H score22 First: 20.07.2026 15:30 Last: 20.07.2026 15:30 Sources 1

How related: Two back-to-back follow-up reports from Group-IB and Kaspersky detailed another module dubbed HOLLOWGRAPH that turns Microsoft 365 calendars into covert C2 channels.

About this happening: HollowGraph is a Windows espionage campaign that abuses a compromised Microsoft 365 calendar and Microsoft Graph API as a covert two-way C2 channel. Group-IB s...

HollowGraph Windows malware uses Microsoft 365 calendars for covert C2

Malware Activity
H score15 First: 20.07.2026 15:30 Last: 20.07.2026 15:30 Sources 1

How related: "Using the Microsoft Graph API, it treats the compromised mailbox's calendar as a two-way dead-drop: operators plant tasking as calendar events, and the implant exfiltrates stolen files by creating its own events with encrypted data attached," Group-IB noted.

About this happening: HollowGraph is a Windows malware activity that abuses a compromised Microsoft 365 calendar and Microsoft Graph API as covert C2, hiding tasking in far-future *...

Dental clinic hit by network compromise

Incident
H score12 First: 20.07.2026 12:07 Last: 20.07.2026 12:07 Sources 1

About this happening: A dental clinic suffered an unauthorized compromise after a threat actor used Google Gemini CLI to run C&C infrastructure that controlled eight computers and r...

GoSerpent malware activity targeting Southeast Asian entities

Malware Activity
H score26 First: 17.07.2026 11:46 Last: 17.07.2026 11:46 Sources 1

About this happening: GoSerpent is being used in cyber attacks against entities in Southeast Asia, with the activity focused on long-term access, intelligence gathering, and data...

DoNot Team Bangladesh military and defence espionage campaign

Campaign
H score38 First: 17.07.2026 11:46 Last: 17.07.2026 11:46 Sources 1

About this happening: A DoNot Team espionage campaign targeted Bangladesh's military and defence establishments, using spear-phishing RTF files to deliver a DLL implant and establish ...

Timeline

  1. 17.08.2026 20:41 1 articles · 4h ago

    HOLLOWGRAPH is first detected in the wild

    Detection Ioc Update

    HOLLOWGRAPH was first detected in the wild on June 7, 2026, establishing the earliest confirmed sighting of the .NET NativeAOT-compiled DLL used for Microsoft 365 calendar-based command-and-control and file exfiltration.

    Show sources
  2. 17.08.2026 20:41 2 articles · 4h ago

    Researchers detail HOLLOWGRAPH calendar-based command-and-control

    Initial Disclosure

    HOLLOWGRAPH turns Microsoft 365 calendars into a covert command-and-control channel by abusing the Microsoft Graph API to receive commands and exfiltrate files, while DNS tunneling refreshes Microsoft Entra ID credentials used to authenticate to the Graph API. Operators hide tasking in future-dated calendar events, including events set to 13 May 2050, with payloads attached as files.

    Show sources