Security researchers report the discovery of HollowGraph, an espionage malware implant that abuses Microsoft 365 mailbox calendars to act as a covert command-and-control (C2) channel and a method for exfiltrating stolen data. Multiple outlets, citing Group-IB, say the malware leverages Microsoft Graph API traffic so activity appears similar to legitimate Microsoft cloud usage. The operator hides commands inside calendar events placed far in the future (including dates in 2050), reducing the likelihood that mailbox owners will notice. HollowGraph retrieves attacker instructions from these calendar entries and processes attachments associated with the events.

Sources also describe how the malware can package and upload stolen files back into the same Microsoft 365 calendar system, again using calendar events to smuggle data out. The reports indicate the malware uses encrypted data in attachments and that its communications are designed to blend into normal application-driven Graph requests rather than making direct calls to attacker-controlled infrastructure. Group-IB links the campaign with high confidence to the Cavern backdoor framework, and notes targeted indicators consistent with Israeli organizations, while stopping short of definitive attribution beyond the framework connection.