HollowGraph: Espionage Malware Hides C2 in Microsoft 365 Calendar Events Dated 2050 — No Attacker Server, No Patch, Traffic Indistinguishable from Outlook
HollowGraph is a .NET DLL implant that uses a compromised Microsoft 365 account’s calendar as a two-way dead drop for command-and-control — hiding operator instructions and stolen files in calendar events dated May 13, 2050. All traffic flows through Microsoft’s Graph API. No attacker-owned server. No unusual network destination. No patch. Group-IB identified 12 infected systems targeting Israeli entities, linked with high confidence to the Cavern C2 framework and low confidence to Iranian-nexus Lyceum. The technique is universally reusable against any organization running Microsoft 365.
