HollowGraph malware uses hijacked Microsoft 365 calendars to steal data

A fresh espionage campaign has turned Microsoft 365’s calendar feature into an unlikely data exfiltration channel. Security researchers at Group-IB have uncovered a new implant called HollowGraph that hijacks legitimate Microsoft Graph API traffic to smuggle stolen files and operator instructions under the guise of routine calendar events—even ones scheduled for the year 2050. By blending malicious payloads with normal business communications, the malware evades traditional network defenses that monitor for unusual outbound traffic.
A calendar that never forgets—or gets caught
HollowGraph doesn’t just send data; it embeds stolen files as attachments to calendar events that appear to be scheduled decades in the future. Because these events are technically valid and use Microsoft’s own infrastructure, they bypass email filters and endpoint monitoring tools that typically flag suspicious file transfers. The malware abuses Microsoft Graph API, a legitimate integration layer used by millions of organizations, to read incoming “tasking” commands and upload pilfered documents without raising red flags.
Why this matters
This technique represents a shift in attacker innovation, exploiting trust in cloud ecosystems rather than brute-forcing perimeter defenses. For defenders, it underscores the need to inspect not just payloads but metadata and timing anomalies in legitimate API calls. Organizations relying on Microsoft 365 should review Graph API audit logs and implement stricter conditional access policies to limit abuse of this high-trust channel. The hollow promise of “future-proof” calendars has never been more costly.
Source: The Hacker News. AI-assisted editorial synthesis — TechnoExpress.

