Outlook malware hides commands in fake 2050 calendar events
A spyware tool called Project CAV3RN hides its commands in Outlook calendar events set for 2050. It steals Microsoft 365 login details and uses them to send and receive secret messages without raising suspicion.
- Report priority
- Medium
- Targets
- Microsoft Outlook+3 more
How it works
- The malware sends fake calendar events for May 13, 2050, to a victim's Outlook account.
- It then reads and writes hidden messages in those events to send commands and steal data without being noticed.
What to do
Check if you're an Israeli organization using Microsoft 365 and Outlook for work. If so, your account may be at risk if you've recently opened suspicious emails or links.
Update your Microsoft 365 security settings to monitor unusual calendar activity. Contact your IT team or Microsoft support to check for unauthorized access to your Outlook calendar or Microsoft Entra ID credentials.
Technical details
Affected software: Microsoft Outlook, Microsoft 365, Microsoft Graph API, Microsoft Entra ID
An attacker sends a fake email with a malicious link to an Israeli organization's employee. When the employee clicks it, the malware installs itself on their Outlook. It creates a fake calendar event for May 13, 2050, and hides secret messages there. Later, the hacker checks that event to send new commands or steal files from the victim's Microsoft 365 account.
This malware, linked to the Project CAV3RN framework, abuses Microsoft Outlook calendar events scheduled for May 13, 2050, to hide command-and-control (C2) traffic. The component, named AzureCommunication.dll, replaces an older HTTP/WebSocket C2 module and uses a compromised Microsoft 365 mailbox to send and receive encrypted commands via Microsoft Graph API. Attackers authenticate through Microsoft Entra ID with OAuth 2.0 credentials, embedding malicious data in calendar events that appear decades in the future, reducing detection risk.
Commands are stored in events with subjects like "Event ID: [number]" and encrypted with RSA-wrapped AES-256-GCM, while stolen data is sent as attachments labeled "Boss Report ID: 1500." As a fallback, the malware uses DNS AAAA responses to restore Microsoft Graph credentials if cloud authentication fails. Targeted against Israeli organizations, this technique blends with legitimate Microsoft 365 activity to evade scrutiny.
References
- securelist.com · 120757 Cyber Security News
- any.run · phantomenigma-research Cyber Security News
- darkreading.com · gigawiper-threat-actors-choose-their-own-destructive-attack DarkReading
- infosecurity-magazine.com · hollowgraph-microsoft-calendars Infosecurity Magazine
- securityweek.com · new-hollowgraph-malware-abuses-microsoft-365-calendar-for-cc-communication SecurityWeek