HackMyIP
← Back to News
2026-07-21 SecurityWeek

HollowGraph Malware Uses Microsoft 365 Calendar as Dead-Drop C&C Channel

MalwareCloud SecurityThreat Intel

HollowGraph, a newly documented malware toolkit, is leveraging a compromised Microsoft 365 account's calendar as a two-way dead-drop for command-and-control (C&C) communication, according to researchers. The technique allows attackers to blend malicious traffic into legitimate cloud services, making detection significantly harder for traditional network defenders and secure email gateways.

The malware operates by creating and modifying calendar events on an already-compromised Microsoft 365 tenant to exchange commands and stage exfiltrated data. By piggybacking on a trusted cloud platform, HollowGraph sidesteps common security controls such as domain reputation filtering, IP blacklists, and URL inspection. This approach places it in the same category as other living-off-the-land cloud (LOTL-cloud) threats that have proliferated as enterprises increasingly rely on SaaS platforms for day-to-day operations.

Security teams are advised to audit Microsoft 365 unified audit logs for anomalous calendar event creation, scrutinize OAuth consent grants, and review mailbox activity for unusual patterns tied to single accounts. Defenders can use a DNS leak test to verify whether internal traffic is being inadvertently exposed through misconfigured endpoints, while a WHOIS lookup can help analysts trace suspicious infrastructure connected to the campaign. Given the toolkit's reliance on valid credentials, organizations should enforce multi-factor authentication and routinely run a password checker to identify compromised employee accounts before they are weaponized.

HollowGraph is part of a broader trend in which adversaries abuse legitimate productivity tools for covert communications, turning everyday SaaS features into stealthy attack infrastructure. As cloud-based C&C channels continue to evolve, security teams must shift from perimeter-based detection toward identity- and behavior-centric monitoring to identify and contain these intrusions before data exfiltration occurs.

Source: SecurityWeek →

Related Tools

Check whether this kind of story affects you — free, no signup:

My IP →IP Lookup →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is my IP and why it matters →IP address security →How to stop being tracked online →