Critical Microsoft 365 Flaw Lets Attackers Send Malware via Calendar Invites
Key Takeaways A novel malware, HOLLOWGRAPH, leverages Microsoft 365 calendars for covert command and control. The malware disguises malicious instructions and data exfiltration within...
Key Takeaways
- A novel malware, HOLLOWGRAPH, leverages Microsoft 365 calendars for covert command and control.
- The malware disguises malicious instructions and data exfiltration within legitimate-looking calendar invites, specifically dated May 13, 2050.
- HOLLOWGRAPH also uses DNS tunneling for credential refreshing, bypassing traditional security measures.
- Attributed with high confidence to the Cavern backdoor framework, linked to an Iran-nexus threat actor.
- The campaign is highly targeted, focusing on Israeli organizations for espionage purposes.
Cybersecurity researchers have uncovered a sophisticated new malware variant, dubbed HOLLOWGRAPH, which exploits Microsoft 365 calendars to establish a clandestine communication channel with its operators. This stealthy threat transforms ordinary calendar invitations into a “dead drop” system, allowing attackers to issue commands and exfiltrate data without raising immediate suspicion.
Table Of Content
HOLLOWGRAPH is a .NET-compiled malicious component that abuses the Microsoft Graph API through a compromised Microsoft 365 account. This method enables it to weaponize a mailbox’s calendar, converting it into a two-way, covert communication hub for malicious activity. Critically, the malware routes all its traffic through trusted Microsoft cloud infrastructure, making its network activity difficult to distinguish from legitimate business operations.
The malware’s functionality is streamlined, supporting only “get” and “send” commands. According to a report by Group-IB identified, threat actors embed their instructions within calendar events. Conversely, HOLLOWGRAPH exfiltrates stolen files by generating its own encrypted events, concealing the illicit data within file attachments. To maintain its covert nature and prevent detection by the mailbox owner, all malicious events are scheduled far into the future, specifically for May 13, 2050, ensuring they never appear on any active calendar schedule.
Sneaky Credential Refresh via DNS
Beyond its calendar-based communication, HOLLOWGRAPH employs a secondary, equally subtle channel for maintaining persistence: DNS tunneling. This mechanism utilizes IPv6 AAAA record queries directed to the domain “cloudlanecdn[.]com.” This method allows the malware to surreptitiously refresh its Microsoft Entra ID (formerly Azure AD) login credentials. These updated credentials are then stored in a file camouflaged as a standard log file, named logAzure.txt.
All data exchanged through the Graph API channel is secured using a hybrid encryption scheme involving RSA and AES-256-GCM. To ensure cryptographic isolation, separate key pairs are utilized for incoming commands and outgoing exfiltrated data.
Group-IB has attributed HOLLOWGRAPH with high confidence to the Cavern backdoor framework. This modular command-and-control toolkit has been previously documented by Check Point Research and is associated with an Iran-nexus actor tracked as “Cavern Manticore.” The attribution is based on shared command syntax and identical self-command codes observed across both malware families. Investigators also noted some technical overlaps with Lyceum, an Iranian threat group linked to Iran’s Ministry of Intelligence and Security and considered a sub-group of OilRig, though this connection is held with lower confidence.
This particular campaign is not widespread. Group-IB identified only 12 compromised systems, with a mere three actively communicating with the attackers during the observation period. Activity has been traced back to at least June 3, 2026, with the most recent communication noted on July 9, 2026. All indicators, including the compromised mailboxes, uploaded malware samples, and associated Cavern files, suggest a precise focus on Israeli organizations. This narrow targeting strongly indicates a deliberate espionage operation rather than opportunistic hacking.
What You Should Do
- Monitor Calendar Events: Actively search for calendar events dated May 13, 2050. Also, look for subjects that are bare GUIDs or follow “Event ID:” and “Boss{..}ID{..}” naming conventions, and attachments named File{n}.txt.
- Audit Microsoft Graph Activity: Scrutinize Microsoft Graph API logs for any application-driven calendar modifications that appear unusual or unauthorized.
- Monitor DNS Queries: Look for anomalous AAAA DNS queries, particularly those directed to the domain “cloudlanecdn[.]com.”
- File System Monitoring: Watch for the creation or modification of the “logAzure.txt” file in unexpected locations.
- Enhance Cloud Visibility: Strengthen monitoring capabilities for cloud environments to detect abuse of trusted cloud services.
- Tighten Access Controls: Implement stricter controls around OAuth application permissions and Microsoft Entra ID credentials to mitigate the risk of similar attacks.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.