Microsoft 365 calendar events hide spyware commands

Published July 17, 2026

Microsoft 365 accounts infected with HOLLOWGRAPH spyware use fake calendar events to secretly receive commands and send stolen data. Attackers hide commands in calendar events set for May 13, 2050, and infected devices reply with stolen information.

Report priority
High
Targets
Microsoft Entra ID

How it works

Attackers hijack a Microsoft 365 account and install spyware that uses Outlook calendar events dated May 13, 2050, to secretly send and receive encrypted commands and stolen data through Microsoft Graph.

What to do

Check if your Microsoft 365 account was compromised by looking for unusual calendar events dated May 13, 2050, or unexpected data leaks in your files.

If your account is infected, reset your Microsoft 365 password immediately and review all recent calendar events for suspicious entries. Microsoft has not released a patch, so focus on monitoring for unusual activity and securing your account.

Technical details

Affected software: Microsoft Entra ID

An attacker breaks into a company's Microsoft 365 account and installs the HOLLOWGRAPH spyware. The malware logs into the account using stolen credentials and creates fake calendar events for May 13, 2050, to hide commands. The infected device checks this future date window every day and replies with stolen files or messages when prompted.

A cyberespionage malware called HOLLOWGRAPH (linked to the Cavern backdoor framework) abuses Microsoft 365 calendar events to hide command-and-control (C2) traffic. The implant uses a compromised mailbox's default calendar, specifically, events scheduled for May 13, 2050, between 22:00, 23:00 UTC, to exchange encrypted commands and stolen data via Microsoft Graph. Attackers create events containing commands (e.g., downloading attachments), while infected systems reply with encrypted results (e.g., exfiltrated files or status updates).

The technique evades detection by relying on a future-dated calendar window unlikely to be manually inspected. The malware authenticates to Microsoft Entra ID using stolen credentials (recovered via DNS AAAA responses) and communicates through AzureCommunication.dll, a module replacing an older HTTP/WebSocket-based component (n-HTCommp.dll). This modular design allows operators to issue tasks via a seven-character agent identifier, enabling persistent, undetectable communication within a victim's mailbox.

Kaspersky and Group-IB independently linked the activity to the Project CAV3RN framework, confirming at least 12 infected systems with active C2 channels.