Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Abbott Investigates ShinyHunters Data Breach Claim Affecting Healthcare Systems
July 21, 2026
Critical Microsoft Defender XDR Flaw Hides Public Connections
July 21, 2026
Critical SonicWall VPN Vulnerabilities Exploited in the Wild
July 21, 2026
Home/CyberSecurity News/Critical Microsoft 365 Flaw Lets Attackers Send Malware via Calendar Invites
CyberSecurity News

Critical Microsoft 365 Flaw Lets Attackers Send Malware via Calendar Invites

Key Takeaways A novel malware, HOLLOWGRAPH, leverages Microsoft 365 calendars for covert command and control. The malware disguises malicious instructions and data exfiltration within...

David kimber
David kimber
July 21, 2026 3 Min Read
4 0

Key Takeaways

  • A novel malware, HOLLOWGRAPH, leverages Microsoft 365 calendars for covert command and control.
  • The malware disguises malicious instructions and data exfiltration within legitimate-looking calendar invites, specifically dated May 13, 2050.
  • HOLLOWGRAPH also uses DNS tunneling for credential refreshing, bypassing traditional security measures.
  • Attributed with high confidence to the Cavern backdoor framework, linked to an Iran-nexus threat actor.
  • The campaign is highly targeted, focusing on Israeli organizations for espionage purposes.

Cybersecurity researchers have uncovered a sophisticated new malware variant, dubbed HOLLOWGRAPH, which exploits Microsoft 365 calendars to establish a clandestine communication channel with its operators. This stealthy threat transforms ordinary calendar invitations into a “dead drop” system, allowing attackers to issue commands and exfiltrate data without raising immediate suspicion.

Table Of Content

  • Key Takeaways
  • Sneaky Credential Refresh via DNS
  • What You Should Do

HOLLOWGRAPH is a .NET-compiled malicious component that abuses the Microsoft Graph API through a compromised Microsoft 365 account. This method enables it to weaponize a mailbox’s calendar, converting it into a two-way, covert communication hub for malicious activity. Critically, the malware routes all its traffic through trusted Microsoft cloud infrastructure, making its network activity difficult to distinguish from legitimate business operations.

The malware’s functionality is streamlined, supporting only “get” and “send” commands. According to a report by Group-IB identified, threat actors embed their instructions within calendar events. Conversely, HOLLOWGRAPH exfiltrates stolen files by generating its own encrypted events, concealing the illicit data within file attachments. To maintain its covert nature and prevent detection by the mailbox owner, all malicious events are scheduled far into the future, specifically for May 13, 2050, ensuring they never appear on any active calendar schedule.

Sneaky Credential Refresh via DNS

Beyond its calendar-based communication, HOLLOWGRAPH employs a secondary, equally subtle channel for maintaining persistence: DNS tunneling. This mechanism utilizes IPv6 AAAA record queries directed to the domain “cloudlanecdn[.]com.” This method allows the malware to surreptitiously refresh its Microsoft Entra ID (formerly Azure AD) login credentials. These updated credentials are then stored in a file camouflaged as a standard log file, named logAzure.txt.

All data exchanged through the Graph API channel is secured using a hybrid encryption scheme involving RSA and AES-256-GCM. To ensure cryptographic isolation, separate key pairs are utilized for incoming commands and outgoing exfiltrated data.

Group-IB has attributed HOLLOWGRAPH with high confidence to the Cavern backdoor framework. This modular command-and-control toolkit has been previously documented by Check Point Research and is associated with an Iran-nexus actor tracked as “Cavern Manticore.” The attribution is based on shared command syntax and identical self-command codes observed across both malware families. Investigators also noted some technical overlaps with Lyceum, an Iranian threat group linked to Iran’s Ministry of Intelligence and Security and considered a sub-group of OilRig, though this connection is held with lower confidence.

This particular campaign is not widespread. Group-IB identified only 12 compromised systems, with a mere three actively communicating with the attackers during the observation period. Activity has been traced back to at least June 3, 2026, with the most recent communication noted on July 9, 2026. All indicators, including the compromised mailboxes, uploaded malware samples, and associated Cavern files, suggest a precise focus on Israeli organizations. This narrow targeting strongly indicates a deliberate espionage operation rather than opportunistic hacking.

What You Should Do

  • Monitor Calendar Events: Actively search for calendar events dated May 13, 2050. Also, look for subjects that are bare GUIDs or follow “Event ID:” and “Boss{..}ID{..}” naming conventions, and attachments named File{n}.txt.
  • Audit Microsoft Graph Activity: Scrutinize Microsoft Graph API logs for any application-driven calendar modifications that appear unusual or unauthorized.
  • Monitor DNS Queries: Look for anomalous AAAA DNS queries, particularly those directed to the domain “cloudlanecdn[.]com.”
  • File System Monitoring: Watch for the creation or modification of the “logAzure.txt” file in unexpected locations.
  • Enhance Cloud Visibility: Strengthen monitoring capabilities for cloud environments to detect abuse of trusted cloud services.
  • Tighten Access Controls: Implement stricter controls around OAuth application permissions and Microsoft Entra ID credentials to mitigate the risk of similar attacks.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackHackerMalwareSecurityThreat

Share Article

David kimber

David kimber

David is a penetration tester turned security journalist with expertise in mobile security, IoT vulnerabilities, and exploit development. As an OSCP-certified security professional, David brings hands-on technical experience to his reporting on vulnerabilities and security research. His articles often feature detailed technical analysis of exploits and provide actionable defense recommendations. David maintains an active presence in the security research community and has contributed to multiple open-source security tools.

Previous Post

Furtex Linux Toolkit Aids Post-Exploitation and Evasion for Red Teams

Next Post

New PAM Guide Reveals Privilege Escalation Paths Attackers Exploit

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical Gitea CVE-2024-4696 allows private repo writes, workflow triggers
July 21, 2026
Critical Vulnerability in NVIDIA DGX Systems Puts Power Grid at Risk
July 21, 2026
Critical PAN-OS Vulnerability Exploited by Qilin Ransomware Gang
July 21, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
David kimber
David kimber
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us