MalwareJul 20, 2026
Researchers Uncover HOLLOWGRAPH: Malware That Hides Inside Microsoft 365 Calendar Invites
New HOLLOWGRAPH malware uses Microsoft 365 calendar invites for C2 and data exfiltration.
Vendor Watch
Run Group-IB?
Get an email when a reviewed story names Group-IB, usually within the hour.
Free. Your list stays private and never appears in a subject line. One click stops it. How Vendor Watch works
Summary
Researchers have discovered a new Windows malware strain named HOLLOWGRAPH that leverages Microsoft 365 calendar invites as a covert channel for command and control (C2) and data exfiltration. This sophisticated technique allows attackers to blend malicious communications with legitimate enterprise traffic, making detection significantly more challenging. Group-IB's research highlights the novel use of a common productivity tool for malicious purposes.
Entities
Microsoft 365 (product)Group-IB (vendor)