Back to feed
Dev.to
Dev.to
7/20/2026
HollowGraph Malware Uses Microsoft 365 Calendar Events as Dead-Drop C2 Channel

HollowGraph Malware Uses Microsoft 365 Calendar Events as Dead-Drop C2 Channel

Short summary

Group-IB disclosed HollowGraph, a .NET espionage implant that uses Microsoft 365 calendar events dated 2050 as a covert C2 dead-drop channel via the Microsoft Graph API. The malware supports GET and SEND commands with RSA+AES-256-GCM encryption, runs a secondary DNS tunneling channel for credential refresh, and has infected at least 12 systems in a campaign targeting Israeli organizations. Detection requires monitoring M365 audit logs for far-future calendar events and unusual DNS IPv6 queries.

  • HollowGraph malware hides C2 traffic in M365 calendar events dated May 2050 via Microsoft Graph API
  • Hybrid RSA+AES-256-GCM encryption with separate key pairs for inbound and outbound channels
  • At least 12 systems infected in targeted espionage campaign against Israeli organizations

Generated with AI, which can make mistakes.

Is this a good recommendation for you?

Comments

Failed to load comments. Please try again.

Explore more