Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Microsoft 365 Calendars Hacked: A New Form of Espionage Malware Lurks in the Shadows


Malware has discovered a new way to hide within Microsoft 365 calendars as part of the HOLLOWGRAPH campaign. This espionage malware uses legitimate calendar events to conceal its malicious activities and blend into trusted Microsoft Graph services, making it difficult to detect.

  • The latest malware campaign, HOLLOWGRAPH, uses Microsoft 365 calendars to hide malicious code.
  • The malware targets specific dates in the future and creates appointments to store stolen files or encrypted tasking.
  • HOLLOWGRAPH is insidious due to its ability to blend into legitimate Microsoft Graph API services.
  • The malware has been linked to an Iranian-linked espionage group with low confidence, but conclusive evidence is lacking.
  • The campaign appears to be narrowly targeted, infecting only 12 systems identified so far.



  • Malware has become increasingly sophisticated, evolving to evade traditional security measures and exploit trust within organizations. The latest example of this trend is the discovery of a new espionage malware campaign that utilizes Microsoft 365 calendars as a hiding place for malicious code. Researchers at Group-IB have identified this malware component, dubbed HOLLOWGRAPH, which swaps traditional command-and-control servers with compromised calendar events, effectively concealing its malicious activities within legitimate Microsoft 365 infrastructure.

    The HOLLOWGRAPH malware targets specific dates in the future – in this case, May 13, 2050 – and creates new appointments to store stolen files or encrypted tasking. The malicious code is surprisingly lean, performing minimal actions beyond fetching instructions from calendar events, stashing stolen files in another appointment, and periodically retrieving fresh credentials via DNS tunneling channels.

    What makes HOLLOWGRAPH particularly insidious is its ability to blend into the Microsoft Graph API, making it nearly indistinguishable from legitimate Microsoft 365 applications. The malware takes advantage of services already trusted within organizations, rendering the malicious activity far less conspicuous than more traditional forms of malware that rely on attacker-controlled infrastructure.

    Researchers at Group-IB have linked HOLLOWGRAPH to an Iranian-linked espionage group called Lyceum with low confidence, suggesting a possible connection between the two campaigns. However, the researchers stopped short of pinning the operation directly on this crew due to lack of conclusive evidence.

    The campaign appears to be narrowly targeted, with only 12 infected systems identified, and three of which communicated with the compromised mailbox during the observed period. The malware samples were uploaded from Israel, pointing to a focused espionage operation rather than a broad smash-and-grab. This highlights the increasing sophistication of modern espionage campaigns and their ability to exploit trusted services within organizations.

    Microsoft 365 calendars have become an unlikely hiding place for malicious code, demonstrating the evolving nature of cyber threats. As security measures continue to evolve in response, it is essential for organizations to remain vigilant and implement robust security protocols to protect themselves against such sophisticated attacks.

    Related Information:
  • https://www.ethicalhackingnews.com/articles/Microsoft-365-Calendars-Hacked-A-New-Form-of-Espionage-Malware-Lurks-in-the-Shadows-ehn.shtml

  • https://www.theregister.com/security/2026/07/20/microsoft-365-calendars-become-spy-drop-boxes-in-hollowgraph-campaign/5274982


  • Published: Mon Jul 20 10:51:56 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us