Microsoft: Watch out - that Microsoft Calendar invite dated 2050 could be hiding stolen files and worse

Microsoft: Watch out - that Microsoft Calendar invite dated 2050 could be hiding stolen files and worse

HollowGraph Malware Abuses Microsoft Graph API to Target Israeli Entities

Security researchers at Group-IB have uncovered a novel malware strain, HollowGraph, designed to exfiltrate sensitive files from compromised systems by leveraging Microsoft Graph API and hijacked Microsoft 365 calendars.

The malware stands out for its stealthy command-and-control (C2) mechanism, which evades detection by embedding instructions in future-dated calendar entries (set for 2050) within a victim’s Microsoft 365 account. After executing commands and harvesting data, HollowGraph encrypts and attaches stolen files to calendar events, blending malicious traffic with legitimate Microsoft Graph activity.

Key Details:

  • Targets: At least 12 Israeli entities, with three systems still actively communicating with attacker infrastructure during Group-IB’s investigation.
  • Infection Vector: Compromised Microsoft 365 accounts, granting access to Microsoft Graph API.
  • Exfiltration Method: Encrypted data is sent via calendar event attachments, appearing as routine traffic.
  • Attribution: While Group-IB noted technical overlaps with Lyceum (an Iranian-linked threat group tied to OilRig), the connection remains low-confidence due to insufficient distinct evidence.

The malware’s framework, Cavern, shares similarities with a .NET backdoor previously used by Lyceum, including command structures and plugin mechanisms. However, researchers emphasize that these parallels do not confirm attribution.

HollowGraph’s abuse of trusted cloud services highlights an evolving tactic to bypass traditional security monitoring, posing challenges for defenders relying on network traffic analysis.

Source: https://www.techradar.com/pro/security/watch-out-that-microsoft-calendar-invite-dated-2050-could-be-hiding-stolen-files-and-worse

Microsoft TPRM report: https://www.rankiteo.com/company/microsoft-security

"id": "mic1784658331",
"linkid": "microsoft-security",
"type": "Cyber Attack",
"date": "7/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'location': 'Israel'}],
 'attack_vector': 'Compromised Microsoft 365 accounts',
 'data_breach': {'data_encryption': True,
                 'data_exfiltration': True,
                 'sensitivity_of_data': 'High',
                 'type_of_data_compromised': 'Sensitive files'},
 'description': 'Security researchers at Group-IB have uncovered a novel '
                'malware strain, HollowGraph, designed to exfiltrate sensitive '
                'files from compromised systems by leveraging Microsoft Graph '
                'API and hijacked Microsoft 365 calendars. The malware uses '
                'stealthy command-and-control (C2) mechanisms by embedding '
                'instructions in future-dated calendar entries (set for 2050) '
                'within a victim’s Microsoft 365 account. After executing '
                'commands and harvesting data, HollowGraph encrypts and '
                'attaches stolen files to calendar events, blending malicious '
                'traffic with legitimate Microsoft Graph activity.',
 'impact': {'data_compromised': 'Sensitive files'},
 'initial_access_broker': {'entry_point': 'Compromised Microsoft 365 accounts'},
 'investigation_status': 'Ongoing (3 systems still actively communicating with '
                         'attacker infrastructure)',
 'lessons_learned': 'HollowGraph’s abuse of trusted cloud services highlights '
                    'an evolving tactic to bypass traditional security '
                    'monitoring, posing challenges for defenders relying on '
                    'network traffic analysis.',
 'post_incident_analysis': {'root_causes': 'Abuse of Microsoft Graph API and '
                                           'hijacked Microsoft 365 calendars '
                                           'for C2 communication and data '
                                           'exfiltration'},
 'ransomware': {'data_encryption': True, 'data_exfiltration': True},
 'references': [{'source': 'Group-IB'}],
 'response': {'third_party_assistance': 'Group-IB'},
 'threat_actor': 'Lyceum (low-confidence attribution)',
 'title': 'HollowGraph Malware Abuses Microsoft Graph API to Target Israeli '
          'Entities',
 'type': 'Malware',
 'vulnerability_exploited': 'Microsoft Graph API abuse'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.