Dev.to
7/20/2026

HollowGraph Malware Uses Microsoft 365 Calendar Events as Dead-Drop C2 Channel
Short summary
Group-IB disclosed HollowGraph, a .NET espionage implant that uses Microsoft 365 calendar events dated 2050 as a covert C2 dead-drop channel via the Microsoft Graph API. The malware supports GET and SEND commands with RSA+AES-256-GCM encryption, runs a secondary DNS tunneling channel for credential refresh, and has infected at least 12 systems in a campaign targeting Israeli organizations. Detection requires monitoring M365 audit logs for far-future calendar events and unusual DNS IPv6 queries.
- •HollowGraph malware hides C2 traffic in M365 calendar events dated May 2050 via Microsoft Graph API
- •Hybrid RSA+AES-256-GCM encryption with separate key pairs for inbound and outbound channels
- •At least 12 systems infected in targeted espionage campaign against Israeli organizations
Generated with AI, which can make mistakes.
Is this a good recommendation for you?



