Microsoft 365 accounts hijacked to send spy malware
Microsoft 365 accounts were stolen and used to secretly send spyware to other users. Attackers hide malicious files in calendar invites and emails.
- Report priority
- Medium
- Targets
- Microsoft 365
How it works
Attackers steal Microsoft 365 accounts and use them to send fake calendar invites and emails that secretly install spyware on victims' devices.
What to do
Check if your Microsoft 365 account was compromised by reviewing recent calendar invites or emails you didn't send.
Enable multi-factor authentication on your Microsoft 365 account immediately and review all recent calendar invites and sent emails for suspicious activity.
Technical details
An attacker steals a work email account. They send a fake calendar invite to a colleague, embedding spyware inside it. When the colleague opens the invite, the spyware secretly starts tracking their device and messages. The attacker then checks the original account's calendar to see which invites were opened and which devices were infected.
July 21, 2026 New HollowGraph Malware Abuses Microsoft 365 Calendar for C&C Communication Part of a larger toolkit, HollowGraph uses a compromised 365 account’s calendar as a two-way dead-drop.