MalwareJul 20, 2026
Researchers Uncover HOLLOWGRAPH: Malware That Hides Inside Microsoft 365 Calendar Invites
New HOLLOWGRAPH malware uses Microsoft 365 calendar invites for C2 and data exfiltration.
Summary
Researchers have discovered a new Windows malware strain named HOLLOWGRAPH that leverages Microsoft 365 calendar invites as a covert channel for command and control (C2) and data exfiltration. This sophisticated technique allows attackers to blend malicious communications with legitimate enterprise traffic, making detection significantly more challenging. Group-IB's research highlights the novel use of a common productivity tool for malicious purposes.
Entities
Microsoft 365 (product)Group-IB (vendor)