HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050
Using a compromised Microsoft 365 calendar as its command channel, a recently found espionage implant has been smuggling out stolen files as attachments on calendar events dating back to 2050 and planting operator instructions.
According to Group-IB, which gave the malware the name HollowGraph, the method transfers tasking and stolen data through authentic Microsoft Graph API traffic, making the activity appear like regular Microsoft 365 chatter and preventing network controls keyed to attacker-owned destinations from raising any red flags.
The implant is a.NET DLL that only accepts the commands "get" and "send," and it never sends payloads to a server owned by the attacker. Rather, it handles the calendar in the hijacked email as a two-way dead drop.
In order to pull tasking, it...










