{"id":14451,"date":"2026-07-21T10:04:24","date_gmt":"2026-07-21T10:04:24","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/07\/21\/hackers-are-turning-microsoft-365-calendar-invites-into-secret-malware-command-channels\/"},"modified":"2026-07-21T10:04:24","modified_gmt":"2026-07-21T10:04:24","slug":"hackers-are-turning-microsoft-365-calendar-invites-into-secret-malware-command-channels","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/07\/21\/hackers-are-turning-microsoft-365-calendar-invites-into-secret-malware-command-channels\/","title":{"rendered":"Hackers Are Turning Microsoft 365 Calendar Invites Into Secret Malware Command Channels"},"content":{"rendered":"<p>    Hackers Are Turning Microsoft 365 Calendar Invites Into Secret Malware Command Channels<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p class=\"wp-block-paragraph\">A stealthy new malware strain called HOLLOWGRAPH that hijacks Microsoft 365 calendars to secretly communicate with hackers, disguising malicious commands as ordinary calendar invites.<\/p>\n<p class=\"wp-block-paragraph\">HOLLOWGRAPH is a .NET-compiled malware component that <a href=\"https:\/\/cybersecuritynews.com\/new-malware-exploiting-outlook-as-a-communication-channel\/\" target=\"_blank\" rel=\"noreferrer noopener\">abuses the Microsoft Graph API<\/a> through a compromised Microsoft 365 account, turning the mailbox\u2019s calendar into a covert two-way \u201cdead drop\u201d for hackers.<\/p>\n<p class=\"wp-block-paragraph\">The malware supports only two commands, get and send, and instead of contacting a suspicious attacker server, it routes everything through trusted Microsoft cloud infrastructure, making the traffic blend in with normal business activity.<\/p>\n<p class=\"wp-block-paragraph\">According to a Group-IB report, the operators plant instructions as calendar events, while the malware exfiltrates stolen files by creating its own encrypted events, with data hidden inside file attachments.<\/p>\n<p class=\"wp-block-paragraph\">To avoid tipping off the mailbox owner, every malicious event is scheduled 24 years into the future, specifically May 13, 2050, so it never appears on anyone\u2019s actual schedule.<\/p>\n<h2 id=\"h-sneaky-credential-refresh-via-dns\" class=\"wp-block-heading\"><strong>Sneaky Credential Refresh via DNS<\/strong><\/h2>\n<p class=\"wp-block-paragraph\">Beyond the calendar trick, HOLLOWGRAPH uses a second covert channel: DNS tunneling through IPv6 AAAA record queries to a domain called \u201ccloudlanecdn[.]com\u201d. This lets the malware quietly refresh its <a href=\"https:\/\/cybersecuritynews.com\/azure-active-directory-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">Microsoft Entra ID (Azure AD) login credentials<\/a>, storing the updated values in a file disguised as an innocent log file, logAzure.txt.<\/p>\n<p class=\"wp-block-paragraph\">All data moving through the Graph API channel is protected with hybrid RSA and AES-256-GCM encryption, using separate key pairs for incoming commands and outgoing stolen data so the two directions stay cryptographically isolated.<\/p>\n<p class=\"wp-block-paragraph\">Group-IB attributes HOLLOWGRAPH with high confidence to the Cavern backdoor framework, a modular command-and-control toolkit previously documented by Check Point Research and associated with an Iran-nexus actor tracked as \u201cCavern Manticore\u201d.<\/p>\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhfGHzf8kRdWtiukyOkz_YQ2LtHDVS1QPcMMX2P6wyChSgJIYWwte3CHtKB-HdFNJAsYQBKR9QJ-bS0g6e1UXhWX6fUW0HTaR3KLlJQFt-icTEnEvqzE9y4TEl1_9Pm5C4sD0pXO6t0QClo9hg02gzMluNOymbEQwXojnoNmMSnW4uYeG2Xc5Uzqc7cB9RZ\/s1600\/Microsoft%2520365%2520Calendar%2520Invites%2520Into%2520Malware1.webp?ssl=1\" alt=\"\"><\/figure>\n<p class=\"wp-block-paragraph\">The link is based on matching command syntax and shared self-command codes observed in both malware families. Investigators also spotted technical overlaps with Lyceum, an Iranian threat group tied to Iran\u2019s Ministry of Intelligence and Security and considered a sub-group of OilRig, though this connection is held at only low confidence.<\/p>\n<p class=\"wp-block-paragraph\">This isn\u2019t a mass-scale campaign. <a href=\"https:\/\/www.group-ib.com\/blog\/hollowgraph-microsoft-365\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Group-IB identified<\/a> just 12 infected systems, with only about three actively communicating with the attackers during the observation window.<\/p>\n<p class=\"wp-block-paragraph\">Activity has been tracked since at least June 3, 2026, with the most recent communication observed on July 9, 2026. Every indicator the compromised mailbox, uploaded malware samples, and related Cavern files points to a narrow focus on Israeli organizations, suggesting a deliberate espionage operation rather than opportunistic hacking.<\/p>\n<p class=\"wp-block-paragraph\">Organizations can hunt for the malware by looking for calendar events dated 2050-05-13, subjects that are bare GUIDs or follow \u201cEvent ID:\u201d and \u201cBoss{..}ID{..}\u201d naming patterns, and attachments named File{n}.txt.<\/p>\n<p class=\"wp-block-paragraph\">Security teams should also audit Microsoft Graph activity for application-driven calendar changes, monitor for unusual AAAA DNS queries, and watch for the cloudlanecdn[.]com domain and logAzure.txt file.<\/p>\n<p class=\"wp-block-paragraph\">Group-IB recommends organizations strengthen cloud visibility, monitor for abuse of trusted cloud services, and tighten controls around OAuth application permissions and Entra ID credentials to catch similar attacks early.<\/p>\n<p class=\"has-text-align-center has-background wp-block-paragraph\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 87%,rgb(169,184,195) 100%)\"><strong>\u00a0Strengthen Your SOC by Accelerating Threat Detection &amp; Rapid Investigations.\u00a0-&gt;\u00a0<a href=\"https:\/\/any.run\/enterprise\/?utm_source=csn&amp;utm_medium=links&amp;utm_campaign=sandbox&amp;utm_content=enterprise&amp;utm_term=0626#contact-sales\" target=\"_blank\" rel=\"noreferrer noopener\">Integrate ANY.RUN With Your SOC\u00a0<\/a><strong><a href=\"https:\/\/any.run\/enterprise\/?utm_source=csn&amp;utm_medium=links&amp;utm_campaign=sandbox&amp;utm_content=enterprise&amp;utm_term=0626#contact-sales\" target=\"_blank\" rel=\"noreferrer noopener\">Now<\/a><\/strong>.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/microsoft-365-calendar-invites-into-malware\/\">Hackers Are Turning Microsoft 365 Calendar Invites Into Secret Malware Command Channels<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Guru Baran<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/microsoft-365-calendar-invites-into-malware\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Hackers Are Turning Microsoft 365 Calendar Invites Into Secret Malware Command Channels A stealthy new malware strain called HOLLOWGRAPH that hijacks Microsoft 365 calendars to secretly communicate with hackers, disguising malicious commands as ordinary calendar invites. HOLLOWGRAPH is a .NET-compiled malware component that abuses the Microsoft Graph API through a compromised Microsoft 365 account, turning [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63],"tags":[130],"class_list":["post-14451","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/14451"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=14451"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/14451\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=14451"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=14451"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=14451"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}