HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050

HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050
Group-IB has uncovered HollowGraph, a .NET espionage implant that uses a hijacked Microsoft 365 calendar and Microsoft Graph API traffic to receive instructions and exfiltrate stolen files through far-future calendar events. The campaign also uses DNS to refresh Entra ID client-credential details, and Group-IB links the implant to Cavern with high confidence but does not confidently attribute the operation to a known threat actor. #HollowGraph #Microsoft365 #MicrosoftGraph #EntraID #Cavern #cloudlanecdn

Keypoints

  • HollowGraph uses a compromised Microsoft 365 calendar as a two-way dead drop.
  • The implant pulls instructions from a far-future event dated 2050-05-13.
  • Stolen files are encrypted and uploaded as calendar attachments for exfiltration.
  • A DNS channel refreshes Entra ID client credentials from cloudlanecdn[.]com.
  • Group-IB links HollowGraph to Cavern, but the operator remains unattributed.

Read More: https://thehackernews.com/2026/07/hollowgraph-malware-hides-c2-and-stolen.html