top of page

When Tomorrow Becomes the Hiding Place: How HollowGraph Turned Microsoft 365 Calendars into Command-and-Control


Security teams spend years monitoring suspicious domains, malicious IP addresses, and unusual network traffic.

HollowGraph simply chooses a destination no one thinks to inspect.

Instead of communicating with attacker-controlled infrastructure, this espionage implant hides commands and stolen data inside Microsoft 365 calendar events scheduled decades into the future, transforming one of the most trusted enterprise services into an invisible command-and-control channel.



Phase 1 – Hiding in Plain Sight

Unlike traditional malware, HollowGraph never depends on an attacker-owned server for its primary communications.

Instead, it compromises a Microsoft 365 account and treats its calendar as a two-way dead drop, retrieving commands from calendar events and sending stolen information back through new events created years in the future.

Because every interaction occurs through legitimate Microsoft Graph API traffic, network monitoring sees nothing more than ordinary Microsoft 365 activity.



Phase 2 – Turning a Calendar into Infrastructure

The malware searches for calendar events deliberately placed on 13 May 2050, a date chosen because almost nobody will ever navigate that far into their calendar.

Operator instructions are stored as encrypted attachments, while exfiltrated files are uploaded the same way into newly created future events.

Every command and every stolen document becomes part of what appears to be perfectly legitimate calendar synchronization.

The cloud itself becomes the command channel.



Phase 3 – Trust as the Evasion Mechanism

Rather than exploiting a Microsoft vulnerability, HollowGraph exploits trust.

It communicates exclusively through authorized Microsoft Graph APIs while refreshing its Microsoft Entra ID application credentials through DNS records.

The result is malware that blends into normal enterprise cloud activity, bypassing many traditional network controls that focus on suspicious external destinations.

Nothing appears malicious because everything looks legitimate.



Phase 4 – Detecting What Nobody Expected to See

There is no security patch capable of stopping HollowGraph.

Detection depends entirely on visibility.

Security teams must look for application-created calendar events, attachments appearing inside distant future meetings, unusual OAuth applications, new Entra ID client secrets, abnormal Microsoft Graph activity, and DNS requests associated with attacker infrastructure.

The attack succeeds because defenders rarely inspect calendars as potential malware infrastructure.



Defense Measures

Organizations should strengthen their cloud security posture by:

  • Auditing Microsoft Graph API activity.

  • Monitoring application-driven calendar modifications.

  • Restricting OAuth application permissions.

  • Reviewing Entra ID client credentials and newly created client secrets.

  • Hunting for calendar events with unusually distant future dates and suspicious attachments.

  • Monitoring anomalous DNS activity and Graph API usage.

  • Continuously reviewing identity security alongside endpoint monitoring.

Cloud trust must be monitored just as carefully as network traffic.



Conclusions

HollowGraph demonstrates that modern espionage is no longer hiding inside obscure servers or anonymous infrastructure.

It is hiding inside the applications organizations trust every day.

When a calendar becomes a mailbox, a file server, and a command-and-control channel at the same time, the challenge is no longer detecting malicious traffic.

It is recognizing when perfectly legitimate cloud activity has quietly become malicious.



The Hacker News


 
 
 

Comentarios


bottom of page