Microsoft 365 calendar malware steals data
Microsoft 365 users may have their calendar events hijacked to secretly send stolen emails and files to attackers. The malware, called HollowGraph, turns calendar entries into a hidden command channel.
- Report priority
- Medium
- Targets
- Microsoft Graph API
How it works
The malware sends fake calendar events to the victim's Microsoft 365 account, then uses those events to secretly send stolen emails and files to the attacker's mailbox.
What to do
Check if your Microsoft 365 account has unusual calendar events or if your emails or files are missing recently.
Run Microsoft's built-in malware scan or contact Microsoft support to remove HollowGraph and secure your account.
Technical details
Affected software: Microsoft Graph API
An attacker sends a fake calendar invite to your Microsoft 365 account. Your device automatically syncs it. The malware reads that invite as a hidden command, then steals your emails and files. It sends the stolen data back to the attacker's mailbox using another fake calendar event.
HOLLOWGRAPH is a Windows malware implant that repurposes Microsoft 365 calendar events as a covert command-and-control channel. The malware, strongly linked to the Cavern modular backdoor framework, abuses the Microsoft Graph API to fetch instructions from operators and exfiltrate stolen data through a compromised Microsoft 365 mailbox. Attackers can use this to execute arbitrary commands on infected systems while evading detection by blending malicious activity with legitimate calendar traffic.
References
- thehackernews.com · hollowgraph-malware-hides-c2-and-stolen.html TheHackerNews
- bleepingcomputer.com · new-hollowgraph-malware-uses-microsoft-graph-for-stealthy-c2-comms BleepingComputer
- scworld.com · hollowgraph-malware-uses-microsoft-365-calendar-for-command-and-control SC World
- securityonline.info · hollowgraph-malware-microsoft-graph-api SecurityOnline
- gbhackers.com · telepuz-web-injector GBHackers
- infosecurity-magazine.com · hollowgraph-microsoft-calendars Infosecurity Magazine