Established 2026Monday, 20 July 2026
presents

The CloudySec Digest

The wires, edited.
← Front PageThreat Intel Desk
Threat Intel

HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050

Group-IB's HollowGraph analysis reveals espionage malware hiding C2 commands and exfiltrated files inside M365 calendar events set to 2050 — a living-off-the-cloud technique that defeats network-centric detection.

Summary written by editorial AI · Source link below

Filed by THN (Feedburner)1 min readRead at source ↗

A newly discovered espionage implant has been using a hijacked Microsoft 365 calendar as its command channel, planting operator instructions and smuggling out stolen files as attachments on calendar events dated to the year 2050.

Group-IB, which named the malware HollowGraph, says the approach moves tasking and stolen data through legitimate Microsoft Graph API traffic, so the activity looks

Editorial Analysis

Why it matters

Abusing trusted SaaS platforms for C2 renders perimeter and network monitoring ineffective; organisations must shift detection to cloud-native audit logs and behavioural analytics.

What to do

Enable unified audit logging for M365 calendar operations and hunt for calendar events with far-future dates or anomalous attachment patterns.

Board brief

A newly discovered espionage implant hides its command channel inside Microsoft 365 calendar events, challenging conventional security monitoring in cloud-first enterprises.

Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.

Continue at the source
Read the full report at THN (Feedburner)

External link — opens at THN (Feedburner) in a new tab.

§
Continue with

More from the Threat Intel Desk