- Group-IB discovers HollowGraph malware targeting Israeli entities and exfiltrating files via Microsoft Graph API
- Operators hide instructions in future calendar entries, then attach encrypted stolen data to events
- At least 12 systems were compromised; overlaps with Lyceum noted but attribution remains unreliable
Cybercriminals have found a way to communicate with malware installed on victims’ devices through compromised Microsoft Calendar apps, experts have warned.
Security researchers at Group-IB have detailed a recently discovered malware called HollowGraph, designed to exfiltrate sensitive files from compromised devices.
What sets the malware apart is how it communicates with its operators. The best way to detect hidden malware is to monitor traffic entering and exiting a device. This is why cybercriminals do their best to hide this traffic or mix it with other legitimate traffic. In this regard, HollowGraph is unique because it abuses the Microsoft Graph API and a compromised Microsoft 365 mailbox calendar.
A dozen victims
After landing on a device and compromising the Microsoft 365 account, HollowGraph uses that account’s permissions to access Microsoft Graph. Operators create calendar entries containing instructions and place them far in the future (in 2050) to avoid detection. After following the instructions and collecting valuable information, the malware exfiltrates it through the same channel.
Instead of uploading files to a suspicious server, HollowGraph attaches encrypted stolen data to calendar events and sends them via Microsoft Graph. To defenders, all this traffic appears legitimate and generally goes unnoticed.
So far, all the victims are Israeli entities, Group-IB said. Researchers identified at least 12 compromised systems, three of which were still actively communicating with the attackers’ infrastructure during the investigation.
Researchers did not attribute the attack to any known threat actor, but hinted at a potential. They identified technical similarities in command structures and plugin mechanisms between the HollowGraph framework, Cavern, and a .NET backdoor used by Lyceum (an Iranian threat actor associated with OilRig). However, Groupe-IB explicitly emphasizes that these overlaps are not sufficiently distinct and therefore assesses this link with a low level of confidence.
The best antivirus for every budget
Follow TechRadar on Google News And add us as your favorite source to get our news, reviews and expert opinions in your feeds.




