- Group-IB detects HollowGraph malware targeting Israeli entities and exfiltrates files via the Microsoft Graph API
- Operators hide instructions in future calendar entries and then attach encrypted stolen data to events
- At least 12 systems were compromised; overlap with Lyceum noted, but attribution remains low-confidence
Cybercriminals have found a way to communicate with malware installed on victim devices through compromised Microsoft Calendar apps, experts have warned.
Security researchers at Group-IB have described a newly discovered piece of malware called HollowGraph designed to exfiltrate sensitive files from compromised devices.
What makes the malware stand out is the way it communicates with its operators. The best way to spot hidden malware is to monitor the traffic flowing in and out of a device, which is why cybercriminals try their best to hide this traffic or mix it with another, legitimate one. In that regard, HollowGraph is unique because it exploits the Microsoft Graph API and a compromised Microsoft 365 mailbox calendar.
A dozen victims
After landing on a device and compromising the Microsoft 365 account, HollowGraph uses that account’s permissions to access the Microsoft Graph. Operators create calendar entries with instructions and place them far into the future (in the year 2050) to avoid detection. After acting on the instructions and harvesting valuable information, the malware exfiltrates it through the same channel.
Instead of uploading files to a suspicious server, HollowGraph attaches encrypted stolen data to calendar events and sends them through Microsoft Graph. To defenders, all of this traffic appears legitimate and usually flies under their radars.
So far, all the victims are Israeli units, Group-IB said. The researchers identified at least 12 compromised systems, three of which were still actively communicating with the attackers’ infrastructure during the investigation.
The researchers did not attribute the attack to any known threat actor, but hinted at a potential. They identified technical similarities in command structures and plugin mechanisms between HollowGraph’s framework, Cavern, and a .NET backdoor used by Lyceum (an Iranian-nexus threat actor affiliated with OilRig). However, Group-IB explicitly emphasizes that these overlaps are not clear enough, so they assess this connection with low confidence.
The best antivirus for all budgets
Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews and opinions in your feeds.



