Researchers report that the HollowGraph malware uses compromised Microsoft 365 mailboxes and Microsoft Graph APIs to run command-and-control (C2) communications through calendar events. Multiple outlets say the implant hides attacker instructions by embedding them in calendar appointments that are dated far in the future, such as the year 2050, a tactic intended to reduce the chance that mailbox owners review or notice the entries. In the same calendar-based channel, the malware also stores or retrieves encrypted data attachments tied to those calendar events.
According to reporting attributed to Group-IB, HollowGraph is linked with the Cavern backdoor framework as part of a broader espionage toolkit, with technical characteristics that indicate modular capabilities across different components. Sources also describe additional use of legitimate cloud traffic so the behavior appears consistent with normal Microsoft 365 usage, making detection harder.
Bleeping Computer and others add that HollowGraph uses calendar features to receive commands and exfiltrate stolen information, while other reporting notes an additional DNS-based channel for certain updates. Across outlets, the focus is on targeted espionage activity rather than broad malware distribution.