How HollowGraph Malware Uses Microsoft Calendar to Steal Data and What It Means for You

HollowGraph malware stealthily hijacks Microsoft 365 calendars to exfiltrate stolen files via encrypted attachments, targeting Israeli entities and evading detection through Microsoft Graph API.

How HollowGraph Malware Uses Microsoft Calendar to Steal Data and What It Means for You
Sarah Collins

Sarah Collins

Computing Editor

Specializes in PCs, laptops, components, and productivity-focused computing tech.

What is HollowGraph and why does it matter?

HollowGraph is a sophisticated malware designed to steal sensitive data from compromised devices by exploiting Microsoft 365 calendar functionality. It uses legitimate Microsoft Graph API traffic to hide its communication and data theft activities, making it extremely difficult for traditional security tools to detect. The malware is notable for embedding instructions and stolen data inside calendar events dated decades into the future, effectively camouflaging malicious operations within what appears to be standard user calendar activity.

How does HollowGraph operate through Microsoft Calendar?

HOLLOWGRAPH malware turns Microsoft 365 calendars into an espionage channel  - Help Net Security
HOLLOWGRAPH malware turns Microsoft 365 calendars into an espionage channel - Help Net Security

After compromising a user's Microsoft 365 account, HollowGraph leverages existing permissions to interact with the Microsoft Graph API, which is a legitimate interface for Microsoft cloud services. Its operators create calendar entries set far into the future—around the year 2050—to avoid immediate notice. These calendar entries contain encrypted instructions for the malware. When the malware executes these commands and collects sensitive files, it does not send them through typical exfiltration methods like uploading to a suspicious server. Instead, it encrypts the stolen files and attaches them directly to new calendar events. These events are then sent back through Microsoft Graph, blending exfiltrated data with normal calendar traffic that security systems often consider benign.

Who are the targets and what are the risks?

To date, the known victims of HollowGraph appear to be primarily Israeli organizations, with at least a dozen systems confirmed compromised. At least a few of these infected systems were still sending data back to attackers during investigations, highlighting an ongoing threat. The stealthy nature of this attack means that affected users or organizations might only discover the breach after significant damage has occurred. Given the malware’s novel use of trusted Microsoft functionalities for malicious purposes, standard network monitoring and security tools may fail to flag these exfiltration activities, increasing the risk of data loss without obvious warning signs.

What implications does this have for cybersecurity?

🚨 A stealthy new malware strain called HOLLOWGRAPH that hijacks Microsoft  365 calendars to secretly communicate with hackers, disguising malicious  commands as ordinary calendar invites. Full story : https://t.co/XMXvdZzwXN  HOLLOWGRAPH is a .
🚨 A stealthy new malware strain called HOLLOWGRAPH that hijacks Microsoft 365 calendars to secretly communicate with hackers, disguising malicious commands as ordinary calendar invites. Full story : https://t.co/XMXvdZzwXN HOLLOWGRAPH is a .

This malware exemplifies the increasing complexity of cyber threats that exploit trusted cloud services and APIs to evade detection. It underscores the necessity of advanced monitoring capabilities that can analyze behavioral anomalies in cloud applications like Microsoft 365 rather than relying solely on traditional signature-based detection. Security teams need to implement enhanced logging and anomaly detection for Microsoft Graph API activity, especially focusing on unusual calendar data or access patterns. The attack also highlights a shift toward data exfiltration methods that leverage legitimate communication channels to blend in with normal organizational traffic, complicating incident response efforts.

Practical steps to mitigate risk and detect similar threats

  • Regularly audit Microsoft 365 mailbox and calendar activity for unusual entries, such as those set far into the future or with encrypted attachments.
  • Implement strict permissions management and conditional access policies to limit what accounts can do within Microsoft Graph API.
  • Deploy advanced endpoint detection and response tools capable of monitoring API calls and flagging unexpected behaviors.
  • Train security and IT personnel to recognize unconventional exfiltration techniques embedded within standard cloud services.
  • Conduct periodic threat hunting focused on calendar and mailbox abuse patterns within Microsoft 365 environments.

Key takeaway: Vigilance in cloud service monitoring is essential

HOLLOWGRAPH Malware in Microsoft 365 Calendar Events
HOLLOWGRAPH Malware in Microsoft 365 Calendar Events

HollowGraph’s use of Microsoft Calendar as a covert channel for data theft challenges traditional cybersecurity assumptions about trusted services and traffic. Organizations, especially those managing sensitive data, must broaden their security focus to include cloud API activity and unusual calendar behaviors. Without proactive detection and risk management practices tailored to such advanced threats, malware like HollowGraph could continue operating unnoticed, putting critical information at risk.

React to this story

Related Posts