Established 2026Monday, 20 July 2026
presents

The CloudySec Digest

The wires, edited.
← Front PageThreat Intel Desk
Threat Intel

HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050

Group-IB's HollowGraph analysis reveals espionage malware hiding C2 commands and exfiltrated files inside M365 calendar events set to 2050 — a living-off-the-cloud technique that defeats network-centric detection.

Summary written by editorial AI · Source link below

Filed by THN (Feedburner)1 min readRead at source ↗

A newly discovered espionage implant has been using a hijacked Microsoft 365 calendar as its command channel, planting operator instructions and smuggling out stolen files as attachments on calendar events dated to the year 2050.

Group-IB, which named the malware HollowGraph, says the approach moves tasking and stolen data through legitimate Microsoft Graph API traffic, so the activity looks

Editorial Analysis

Framed for the CISO & Security Leaders desk

Why it matters

HollowGraph abuses legitimate Microsoft 365 calendar infrastructure for C2, making detection extremely difficult for organisations that rely heavily on M365 — which includes the vast majority of European enterprises.

What to do

Commission a threat-hunt for anomalous Microsoft 365 calendar activity, particularly events with unusual far-future dates or unexpected file attachments.

Board brief

A newly discovered espionage implant hides its command channel inside Microsoft 365 calendar events, challenging conventional security monitoring in cloud-first enterprises.

Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.

Continue at the source
Read the full report at THN (Feedburner)

External link — opens at THN (Feedburner) in a new tab.

§
Continue with

More from the Threat Intel Desk