Back to Feed
MalwareJul 20, 2026

Researchers Uncover HOLLOWGRAPH: Malware That Hides Inside Microsoft 365 Calendar Invites

New HOLLOWGRAPH malware uses Microsoft 365 calendar invites for C2 and data exfiltration.

Vendor Watch

Run Group-IB?

Get an email when a reviewed story names Group-IB, usually within the hour.

Free. Your list stays private and never appears in a subject line. One click stops it. How Vendor Watch works

Summary

Researchers have discovered a new Windows malware strain named HOLLOWGRAPH that leverages Microsoft 365 calendar invites as a covert channel for command and control (C2) and data exfiltration. This sophisticated technique allows attackers to blend malicious communications with legitimate enterprise traffic, making detection significantly more challenging. Group-IB's research highlights the novel use of a common productivity tool for malicious purposes.

Entities

Microsoft 365 (product)Group-IB (vendor)