Security News

Cybersecurity news aggregator

HIGH Attacks SC Media

HollowGraph malware uses Microsoft 365 calendar for command and control

The HollowGraph malware uses compromised Microsoft 365 credentials to authenticate to the Graph API, establishing a command-and-control channel by hiding instructions and exfiltrated data within files attached to calendar events. The article does not provide a CVSS score, specific affected or fixed software versions, or a direct patch. As a workaround, organizations are advised to monitor Microsoft 365 audit logs for suspicious calendar activity and DNS tunneling patterns.
Read Full Article →

Threat Intelligence HollowGraph malware uses Microsoft 365 calendar for command and control July 20, 2026 Share By SC Staff (Adobe Stock) A new malware component called HollowGraph has been identified by Group-IB that leverages the calendar feature within compromised Microsoft 365 mailboxes to act as a command-and-control channel, according to a recent report by Bleeping Computer. HollowGraph, believed to be part of the Cavern command-and-control framework, targets organizations in Israel for espionage purposes. The malware uses hardcoded credentials to authenticate to the Microsoft Graph API via a compromised Microsoft 365 account. It stores its configuration in a file named logAzure.txt, containing tenant IDs, client secrets, and encryption keys. Commands and exfiltrated data are hidden within files attached to calendar events scheduled for May 13, 2050. HollowGraph supports GET and SEND commands to retrieve instructions and send stolen data, respectively. Communication is secured using a hybrid encryption scheme combining RSA and AES-256-GCM. An additional channel via DNS tunneling is used to update Microsoft Entra ID details. While not definitively attributed to a known actor, technical similarities suggest a link to Iranian-nexus threat actors. Organizations are advised to monitor Microsoft 365 audit logs for suspicious calendar activity and DNS tunneling patterns. Source: Bleeping Computer SC Staff Related Threat Intelligence HelloNet campaign abuses ViPNet update mechanism to target Russian organizations SC Staff July 20, 2026 The HelloNet campaign targets organizations using ViPNet, a Russian information-security product suite commonly used in government and regulated environments. Threat Intelligence 2 charged in New York for laundering $43 million from investment scams SC Staff July 17, 2026 Zhuoying Chen, 27, and Haojie Zhang, 38, are accused of managing a network that transferred at least $43 million to China, based on information published by Bleeping Computer. Threat Intelligence New Russian-speaking threat actor UAT-11795 targets US and Europe with novel malware SC Staff July 17, 2026 UAT-11795 utilizes novel tools, including the Python-based Starland RAT and the PowerShell-based WLDR agent, which operates entirely in-memory with encrypted beaconing and a Runspace execution engine. Related Events Cybercast Better Threat Intelligence Between Public and Private Sectors On-Demand Event Virtual Conference Nationwide Cybersecurity Summit 2025: Safeguarding America’s Digital Future On-Demand Event Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Black Hat DNS Spoofing Deauthentication Attack Dictionary Attack Distributed Scans Dumpster Diving Fault Line Attacks Hybrid Attack Information Warfare Password Cracking You can skip this ad in 5 seconds

Share this article