Hackers Are Turning Microsoft 365 Calendar Invites Into Secret Malware Command Channels

Hackers Are Turning Microsoft 365 Calendar Invites Into Secret Malware Command Channels










A stealthy new malware strain called HOLLOWGRAPH that hijacks Microsoft 365 calendars to secretly communicate with hackers, disguising malicious commands as ordinary calendar invites.

HOLLOWGRAPH is a .NET-compiled malware component that abuses the Microsoft Graph API through a compromised Microsoft 365 account, turning the mailbox’s calendar into a covert two-way “dead drop” for hackers.

The malware supports only two commands, get and send, and instead of contacting a suspicious attacker server, it routes everything through trusted Microsoft cloud infrastructure, making the traffic blend in with normal business activity.

According to a Group-IB report, the operators plant instructions as calendar events, while the malware exfiltrates stolen files by creating its own encrypted events, with data hidden inside file attachments.

To avoid tipping off the mailbox owner, every malicious event is scheduled 24 years into the future, specifically May 13, 2050, so it never appears on anyone’s actual schedule.

Sneaky Credential Refresh via DNS

Beyond the calendar trick, HOLLOWGRAPH uses a second covert channel: DNS tunneling through IPv6 AAAA record queries to a domain called “cloudlanecdn[.]com”. This lets the malware quietly refresh its Microsoft Entra ID (Azure AD) login credentials, storing the updated values in a file disguised as an innocent log file, logAzure.txt.

All data moving through the Graph API channel is protected with hybrid RSA and AES-256-GCM encryption, using separate key pairs for incoming commands and outgoing stolen data so the two directions stay cryptographically isolated.

Group-IB attributes HOLLOWGRAPH with high confidence to the Cavern backdoor framework, a modular command-and-control toolkit previously documented by Check Point Research and associated with an Iran-nexus actor tracked as “Cavern Manticore”.

The link is based on matching command syntax and shared self-command codes observed in both malware families. Investigators also spotted technical overlaps with Lyceum, an Iranian threat group tied to Iran’s Ministry of Intelligence and Security and considered a sub-group of OilRig, though this connection is held at only low confidence.

This isn’t a mass-scale campaign. Group-IB identified just 12 infected systems, with only about three actively communicating with the attackers during the observation window.

Activity has been tracked since at least June 3, 2026, with the most recent communication observed on July 9, 2026. Every indicator the compromised mailbox, uploaded malware samples, and related Cavern files points to a narrow focus on Israeli organizations, suggesting a deliberate espionage operation rather than opportunistic hacking.

Organizations can hunt for the malware by looking for calendar events dated 2050-05-13, subjects that are bare GUIDs or follow “Event ID:” and “Boss{..}ID{..}” naming patterns, and attachments named File{n}.txt.

Security teams should also audit Microsoft Graph activity for application-driven calendar changes, monitor for unusual AAAA DNS queries, and watch for the cloudlanecdn[.]com domain and logAzure.txt file.

Group-IB recommends organizations strengthen cloud visibility, monitor for abuse of trusted cloud services, and tighten controls around OAuth application permissions and Entra ID credentials to catch similar attacks early.

 Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.

The post Hackers Are Turning Microsoft 365 Calendar Invites Into Secret Malware Command Channels appeared first on Cyber Security News.






Guru Baran





Go to cyber-security-news





Posted

in

,

by