Microsoft 365 calendar events hide spyware commands
Microsoft 365 accounts infected with HOLLOWGRAPH spyware use fake calendar events to secretly receive commands and send stolen data. Attackers hide commands in calendar events set for May 13, 2050, and infected devices reply with stolen information.
- Report priority
- High
- Targets
- Microsoft Entra ID
How it works
Attackers hijack a Microsoft 365 account and install spyware that uses Outlook calendar events dated May 13, 2050, to secretly send and receive encrypted commands and stolen data through Microsoft Graph.
What to do
Check if your Microsoft 365 account was compromised by looking for unusual calendar events dated May 13, 2050, or unexpected data leaks in your files.
If your account is infected, reset your Microsoft 365 password immediately and review all recent calendar events for suspicious entries. Microsoft has not released a patch, so focus on monitoring for unusual activity and securing your account.
Technical details
Affected software: Microsoft Entra ID
An attacker breaks into a company's Microsoft 365 account and installs the HOLLOWGRAPH spyware. The malware logs into the account using stolen credentials and creates fake calendar events for May 13, 2050, to hide commands. The infected device checks this future date window every day and replies with stolen files or messages when prompted.
A cyberespionage malware called HOLLOWGRAPH (linked to the Cavern backdoor framework) abuses Microsoft 365 calendar events to hide command-and-control (C2) traffic. The implant uses a compromised mailbox's default calendar, specifically, events scheduled for May 13, 2050, between 22:00, 23:00 UTC, to exchange encrypted commands and stolen data via Microsoft Graph. Attackers create events containing commands (e.g., downloading attachments), while infected systems reply with encrypted results (e.g., exfiltrated files or status updates).
The technique evades detection by relying on a future-dated calendar window unlikely to be manually inspected. The malware authenticates to Microsoft Entra ID using stolen credentials (recovered via DNS AAAA responses) and communicates through AzureCommunication.dll, a module replacing an older HTTP/WebSocket-based component (n-HTCommp.dll). This modular design allows operators to issue tasks via a seven-character agent identifier, enabling persistent, undetectable communication within a victim's mailbox.
Kaspersky and Group-IB independently linked the activity to the Project CAV3RN framework, confirming at least 12 infected systems with active C2 channels.
References
- nvd.nist.gov · CVE-2026-2291 vdb entry
- group-ib.com · hollowgraph-microsoft-365 VPNCentral
- securelist.com · 120757 VPNCentral
- learn.microsoft.com · audit-log-activities VPNCentral
- bleepingcomputer.com · south-korea-discloses-data-breach-impacting-diplomats-worldwide BleepingComputer
- bleepingcomputer.com · chick-fil-a-discloses-data-breach-after-credential-stuffing-attacks BleepingComputer
- scworld.com · trickbot-variant-uses-dns-tunneling-for-command-and-control SC World
- gbhackers.com · trickbot-malware-variant-uses-dns GBHackers
- infosecurity-magazine.com · trickbot-dns-tunneling-c2 Infosecurity Magazine
- blog.exodusintel.com · dnsmasq-dns-remote-heap-buffer-overflow Exodus Intelligence
- notes.austin.exodusintel.com · ZXSRujhnRdC8s1_jdu5khA Exodus Intelligence
- exodusintel.com Exodus Intelligence
- notes.austin.exodusintel.com Exodus Intelligence
- neuracybintel.com · ernst-and-young-discloses-data-breach-via-compromised-third-party-support-system NeuraCybIntel
- openwall.com · 5 Openwall oss-security
- scworld.com · upbound-group-reports-13-million-in-losses-due-to-data-breach-and-fraud SC World
- scworld.com · south-korean-ministry-of-foreign-affairs-data-breach-impacts-thousands SC World
- gbhackers.com · github-actions-into-a-global-botnet GBHackers
- infosecurity-magazine.com · hollowgraph-microsoft-calendars Infosecurity Magazine