Close Menu

    Subscribe to Updates

    Get the latest creative news from infofortech

    What's Hot

    True Fitness & True Yoga to shut in S’pore amid millions in losses

    September 13, 2026

    IDScan Breach Exposes 150 Million Licenses

    September 13, 2026

    Study warns Seattle over-relies on Big Tech; Seattle Times v. Microsoft; Apple’s iPhone Duo echoes the past

    September 12, 2026
    Facebook X (Twitter) Instagram
    InfoForTech
    • Home
    • Latest in Tech
    • Artificial Intelligence
    • Cybersecurity
    • Innovation
    Facebook X (Twitter) Instagram
    InfoForTech
    Home»Cybersecurity»HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050
    Cybersecurity

    HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050

    InfoForTechBy InfoForTechJuly 20, 2026No Comments4 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
    HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050
    Share
    Facebook Twitter LinkedIn Pinterest Telegram Email


    A newly discovered espionage implant has been using a hijacked Microsoft 365 calendar as its command channel, planting operator instructions and smuggling out stolen files as attachments on calendar events dated to the year 2050.

    Group-IB, which named the malware HollowGraph, says the approach moves tasking and stolen data through legitimate Microsoft Graph API traffic, so the activity looks like ordinary Microsoft 365 chatter and network controls keyed to attacker-owned destinations have nothing to flag.

    The implant is a .NET DLL that supports just two commands, get and send, and it never reaches out to an attacker-owned server for payloads. Instead, it treats the compromised mailbox’s calendar as a two-way dead drop.

    To pull tasking, it queries the calendar for an event the operator has planted, buried at 2050-05-13, so the mailbox owner is unlikely to ever scroll to it, and reads its instructions from an attached file. To exfiltrate, it does the reverse: encrypts the stolen file, creates its own far-future event, and uploads the data as one or more attachments.

    Everything moving through the calendar is wrapped in hybrid RSA and AES-256 encryption, with separate key pairs for incoming tasking and outgoing data.

    A second, cruder channel keeps that Graph access alive. Over DNS, HollowGraph refreshes the app’s Entra ID (Azure AD) login details: its tenant ID, client ID, client secret and target mailbox. It decodes those values from IPv6 AAAA records sent back by an attacker domain, cloudlanecdn[.]com, then writes them to logAzure.txt, a file dressed up as a routine log. Those are stored client-credentials, not access tokens, and unlike the calendar traffic this channel runs in the clear.

    Group-IB ties HollowGraph to Cavern with high confidence, on shared command syntax and matching internal tasking. Cavern is a modular backdoor framework that Check Point documented earlier this month and attributed to an Iranian Ministry of Intelligence and Security-linked actor it calls Cavern Manticore, a cluster it says overlaps with the known Iranian groups MuddyWater and Lyceum.

    But the firm link is to the code, not the crew. Group-IB will not name the operator behind this campaign: “Based on the evidence currently available, we cannot confidently attribute this activity to any previously identified threat actor,” it wrote, noting only a low-confidence overlap with Lyceum, a subgroup of the Iranian actor OilRig. The compromised exfiltration mailbox belongs to an Israeli organization, but Group-IB treats that as victim geography, not attribution.

    Group-IB found the implant on at least 12 machines, only about three of them actively talking to the attacker during the analysis window, with victim traffic running from 3 June to 9 July 2026. It reads that small, selective footprint as targeted espionage rather than opportunistic crime, even though the technique behind it could be reused far more widely than this one campaign.

    There is no Microsoft software vulnerability here and no patch to deploy. HollowGraph rides a compromised account and the Graph API’s normal functionality, which is exactly why it is hard to spot. The work is on identity and application permissions plus monitoring, not a patch.

    What to watch for

    Group-IB’s detection advice leans on the malware’s own habits, and the sharpest signals live in the calendar itself. Hunt for events that carry:

    • a far-future date, specifically 2050-05-13;
    • a subject that is a bare GUID, or that matches the operator’s Event ID: or Boss{..}ID{..} naming;
    • attachments named File{n}.txt.

    On the identity side, the firm recommends restricting and auditing the client-credential OAuth apps that can reach Graph and alerting on newly created client secrets, plus the usual Entra ID hygiene of Conditional Access, credential rotation, and anomalous-token detection.

    For detection, audit Microsoft Graph and mailbox activity for application-driven calendar changes: events created, attachments uploaded, or subjects renamed by an app rather than a person. Watch DNS too, for unusually frequent AAAA queries and long, high-entropy subdomains aimed at a single domain. Hunting for cloudlanecdn[.]com and the logAzure.txt config file is the fast first pass, and the full indicator set, including file hashes, is in Group-IB’s report.

    Hiding command-and-control in trusted Microsoft services is not new; attackers have already run it through Outlook inboxes, draft folders and OneDrive. Events parked in 2050, out where no one looks, are simply the latest spot defenders had no reason to inspect. The operator still has no name, and victim traffic was flowing as recently as 9 July, which makes those far-future calendar entries worth a look now.

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    InfoForTech
    • Website

    Related Posts

    What It Does to Your SOC

    September 12, 2026

    AI Agents Help Hackers Compromise 440 PaperCut Servers

    September 12, 2026

    Best Practices for Deception Technology Implementation

    September 12, 2026

    Weekly Update 521: Breach Perception v. Reality

    September 11, 2026

    Claude Used to Automate Exploitation and Data Theft Across Multiple Victims

    September 11, 2026

    180 Android Security Flaws Patched: What to Do

    September 11, 2026
    Leave A Reply Cancel Reply

    Advertisement
    Top Posts

    A Billionaire-Backed Startup Wants to Grow ‘Organ Sacks’ to Replace Animal Testing

    March 23, 2026340 Views

    DoJ Disrupts 3 Million-Device IoT Botnets Behind Record 31.4 Tbps Global DDoS Attacks

    March 20, 202640 Views

    Mayiduo spent S$1M to produce his movie. It broke even & that’s a win in S’pore.

    March 31, 202628 Views

    How is Luckin Coffee expanding rapidly in S’pore while keeping its coffee so cheap?

    April 23, 202621 Views
    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo
    Advertisement
    About Us
    About Us

    Our mission is to deliver clear, reliable, and up-to-date information about the technologies shaping the modern world. We focus on breaking down complex topics into easy-to-understand insights for professionals, enthusiasts, and everyday readers alike.

    We're accepting new partnerships right now.

    Facebook X (Twitter) YouTube
    Most Popular

    A Billionaire-Backed Startup Wants to Grow ‘Organ Sacks’ to Replace Animal Testing

    March 23, 2026340 Views

    DoJ Disrupts 3 Million-Device IoT Botnets Behind Record 31.4 Tbps Global DDoS Attacks

    March 20, 202640 Views

    Mayiduo spent S$1M to produce his movie. It broke even & that’s a win in S’pore.

    March 31, 202628 Views
    Categories
    • Artificial Intelligence
    • Cybersecurity
    • Innovation
    • Latest in Tech
    © 2026 All Rights Reserved InfoForTech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.