Microsoft and Israeli organization: HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050

Microsoft and Israeli organization: HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050

HollowGraph: Espionage Malware Hijacks Microsoft 365 Calendars for Stealthy C2 Operations

Security researchers at Group-IB have uncovered a novel espionage implant, HollowGraph, which leverages a compromised Microsoft 365 calendar as a command-and-control (C2) channel. The malware, a .NET DLL, evades detection by embedding operator instructions and exfiltrating stolen data via calendar events dated to 2050, ensuring they remain hidden from typical user activity.

How HollowGraph Operates

HollowGraph exploits the Microsoft Graph API to blend malicious traffic with legitimate Microsoft 365 communications. Instead of connecting to an attacker-controlled server, it uses the victim’s mailbox calendar as a dead drop:

  • Tasking retrieval: Queries a pre-planted event (dated 2050-05-13) to extract instructions from an attached file.
  • Data exfiltration: Encrypts stolen files, creates a new far-future event, and uploads the data as attachments.
  • Encryption: Uses hybrid RSA and AES-256, with separate key pairs for incoming and outgoing traffic.

A secondary channel maintains persistence via DNS queries to the attacker domain cloudlanecdn[.]com, refreshing Entra ID (Azure AD) credentials (tenant ID, client ID, client secret) stored in a disguised log file (logAzure.txt).

Attribution & Campaign Scope

Group-IB links HollowGraph to Cavern, a modular backdoor framework recently documented by Check Point and attributed to Cavern Manticore, an Iranian threat actor with ties to MuddyWater and Lyceum. However, Group-IB stops short of definitive attribution, citing only a low-confidence overlap with Lyceum (an OilRig subgroup).

The campaign targeted at least 12 machines, with active communication observed between June 3 and July 9, 2026. Victims included an Israeli organization, though Group-IB treats this as geographic targeting rather than a definitive link to the attacker. The limited footprint suggests targeted espionage, though the technique could be repurposed for broader attacks.

Detection & Defense Challenges

HollowGraph exploits legitimate Microsoft 365 functionality, requiring no software vulnerabilities only a compromised account and Graph API access. Key detection indicators include:

  • Calendar anomalies: Events with 2050-05-13 dates, GUID-based subjects (e.g., Event ID:, Boss{..}ID{..}), or attachments named File{n}.txt.
  • Identity risks: Unusual OAuth app permissions, newly created client secrets, or anomalous Entra ID token activity.
  • DNS red flags: Frequent AAAA queries to cloudlanecdn[.]com or high-entropy subdomains.

Broader Implications

This attack underscores the growing trend of abusing trusted cloud services for C2 operations. While previous campaigns have exploited Outlook drafts and OneDrive, HollowGraph’s use of far-future calendar events demonstrates a new evasion tactic. With victim traffic active as recently as July 2026, defenders are advised to scrutinize unusual calendar activity even in the distant future.

Source: https://thehackernews.com/2026/07/hollowgraph-malware-hides-c2-and-stolen.html

Microsoft Threat Intelligence cybersecurity rating report: https://www.rankiteo.com/company/microsoft-threat-intelligence

Israel Innovation Authority רשות החדשנות cybersecurity rating report: https://www.rankiteo.com/company/israelinnovationauthority

"id": "MICISR1784565175",
"linkid": "microsoft-threat-intelligence, israelinnovationauthority",
"type": "Cyber Attack",
"date": "6/2026",
"severity": "60",
"impact": "3",
"explanation": "Attack with significant impact with internal employee data leaks"
{'affected_entities': [{'location': 'Israel',
                        'name': 'Israeli organization',
                        'type': 'Organization'}],
 'attack_vector': 'Compromised Microsoft 365 account with Graph API access',
 'data_breach': {'data_encryption': 'Hybrid RSA and AES-256',
                 'data_exfiltration': True,
                 'personally_identifiable_information': True,
                 'sensitivity_of_data': 'High (PII, credentials)',
                 'type_of_data_compromised': ['Stolen files',
                                              'Entra ID credentials']},
 'date_detected': '2026-06-03',
 'description': 'Security researchers at Group-IB have uncovered a novel '
                'espionage implant, HollowGraph, which leverages a compromised '
                'Microsoft 365 calendar as a command-and-control (C2) channel. '
                'The malware, a .NET DLL, evades detection by embedding '
                'operator instructions and exfiltrating stolen data via '
                'calendar events dated to 2050, ensuring they remain hidden '
                'from typical user activity.',
 'impact': {'data_compromised': 'Stolen files, Entra ID credentials',
            'identity_theft_risk': 'High (PII and credentials compromised)',
            'operational_impact': 'Data exfiltration, unauthorized access',
            'systems_affected': 'Microsoft 365 calendars, Entra ID (Azure AD)'},
 'initial_access_broker': {'backdoors_established': 'HollowGraph .NET DLL',
                           'entry_point': 'Compromised Microsoft 365 account'},
 'investigation_status': 'Ongoing',
 'lessons_learned': 'HollowGraph demonstrates the abuse of trusted cloud '
                    'services (Microsoft 365) for C2 operations, highlighting '
                    'the need for scrutiny of unusual calendar activity and '
                    'OAuth permissions.',
 'motivation': 'Espionage',
 'post_incident_analysis': {'corrective_actions': ['Restrict Graph API '
                                                   'permissions for high-risk '
                                                   'accounts.',
                                                   'Implement anomaly '
                                                   'detection for calendar '
                                                   'events and DNS queries.',
                                                   'Enforce multi-factor '
                                                   'authentication (MFA) for '
                                                   'Entra ID.'],
                            'root_causes': 'Abuse of legitimate Microsoft 365 '
                                           'functionality (Graph API, calendar '
                                           'events) for C2 operations.'},
 'ransomware': {'data_encryption': True, 'data_exfiltration': True},
 'recommendations': ['Monitor calendar events with unusual dates (e.g., '
                     '2050-05-13) or GUID-based subjects.',
                     'Audit OAuth app permissions and Entra ID token activity '
                     'for anomalies.',
                     'Investigate frequent DNS queries to suspicious domains '
                     '(e.g., cloudlanecdn[.]com).',
                     'Implement enhanced monitoring for hybrid encryption '
                     'traffic.'],
 'references': [{'source': 'Group-IB'}, {'source': 'Check Point'}],
 'response': {'enhanced_monitoring': 'Detection of calendar anomalies, OAuth '
                                     'app permissions, Entra ID token '
                                     'activity, DNS queries',
              'third_party_assistance': 'Group-IB'},
 'threat_actor': ['Cavern Manticore', 'Lyceum (low-confidence overlap)'],
 'title': 'HollowGraph: Espionage Malware Hijacks Microsoft 365 Calendars for '
          'Stealthy C2 Operations',
 'type': 'Espionage'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.