HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050
Group-IB's HollowGraph analysis reveals espionage malware hiding C2 commands and exfiltrated files inside M365 calendar events set to 2050 — a living-off-the-cloud technique that defeats network-centric detection.
Summary written by editorial AI · Source link below
A newly discovered espionage implant has been using a hijacked Microsoft 365 calendar as its command channel, planting operator instructions and smuggling out stolen files as attachments on calendar events dated to the year 2050.
Group-IB, which named the malware HollowGraph, says the approach moves tasking and stolen data through legitimate Microsoft Graph API traffic, so the activity looks
Editorial Analysis
Framed for the SOC Analyst desk
This implant uses hijacked M365 calendar events dated to 2050 as a covert C2 and exfiltration channel, blending into legitimate cloud traffic and evading traditional network-based detection.
Create detection rules for M365 calendar events with dates beyond a reasonable horizon (e.g., >2030) and investigate any accounts creating events with binary or encrypted attachments.
A newly discovered espionage implant hides its command channel inside Microsoft 365 calendar events, challenging conventional security monitoring in cloud-first enterprises.
Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.
External link — opens at THN (Feedburner) in a new tab.
More from the Threat Intel Desk
- Attackers Combo Up Evasion Tactics for BEC Phishing20 Jul
- New HollowGraph malware uses Microsoft Graph for stealthy C2 comms20 Jul
- Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign20 Jul
- Hackers were inside South Korea's diplomat training system for 9 months20 Jul
- Romania races to restore land registry after cyberattack disrupts property market20 Jul