HollowGraph: Espionage Malware Hides C2 in Microsoft 365 Calendar Events Dated 2050 — No Attacker Server, No Patch, Traffic Indistinguishable from Outlook
A .NET DLL implant uses a compromised M365 account’s calendar as a two-way dead drop. Commands buried in calendar events dated May 13, 2050. Stolen data attached to the same events. All traffic through graph.microsoft.com. No attacker-owned server. No unusual destination. No Microsoft vulnerability. No patch. Linked to Cavern C2 framework with high confidence. Seven detection steps inside — no signatures, only behavioral hunting.
Read Full Brief →Threats & Attacks
Commands in calendar events dated 2050. All traffic through graph.microsoft.com. No unusual destination. No Microsoft vulnerability. No patch. Linked to Cavern framework, Iranian-nexus Lyceum. Hunt events dated beyond 2030 now.
REST API batch endpoint. Single anonymous request. No preconditions. 500M+ sites. AI model built working exploit chain. Update to 7.0.2 / 6.9.5 immediately.
292/316 tasks. All 7 benchmarks saturated. 32-point gap from token budget. UK AISI confirmed. GPT-5.6 government-gated. Five operational implications.
Just a file copy. 11 shims trusted by every UEFI computer. BlackLotus, Bootkitty. Runs before OS, before EDR, survives OS reinstall. Apply June dbx update.
5,937 login failures = leaked heap memory. MFA bypassed. SYSTEM in minutes. Same playbook across 6 victims. Stolen tokens survive patching — kill all sessions.
Autonomous LLM: initial access to encryption to ransom demand. Ran on victim’s stolen API keys. Same pattern as HollowGraph — legitimate cloud infrastructure as operational terrain.
Intelligence & Deep Dive
The DataWater Intelligence Brief
Weekly CISO-level threat analysis — breaking vulnerabilities, technical depth, zero noise.
