Cybersecurity researchers have uncovered a sophisticated malware strain named HOLLOWGRAPH that leverages Microsoft 365 calendar invites to conduct covert espionage operations. This discovery highlights a novel method by which attackers can infiltrate systems and exfiltrate data while evading traditional detection mechanisms.
HOLLOWGRAPH: A New Espionage Tool
HOLLOWGRAPH is a previously undocumented Windows malware that utilizes Microsoft 365 calendar invites as a covert communication channel. By embedding commands and exfiltrated data within calendar events, the malware blends malicious activities with legitimate enterprise traffic, making detection challenging. This technique allows attackers to issue commands and retrieve stolen files seamlessly.
Connection to Iranian Espionage Activities
Researchers have linked HOLLOWGRAPH to the Cavern backdoor framework, a modular command-and-control toolkit associated with Iranian-nexus activities. The malware has been observed targeting Israeli organizations, indicating a narrowly focused espionage campaign. The earliest recorded activity dates back to June 3, 2026, with ongoing operations as recent as July 9, 2026.
Technical Mechanisms of HOLLOWGRAPH
HOLLOWGRAPH operates by exploiting the Microsoft Graph API through compromised Microsoft 365 accounts. The malware executes two primary commands: ‘get’ and ‘send.’ To receive instructions, the attacker creates a calendar event with embedded commands. The malware checks for these events and extracts the attached data. For exfiltrating stolen files, the malware creates its own calendar events, attaching encrypted files for the attacker to retrieve. This method effectively disguises malicious communications within normal cloud traffic.
Broader Implications and Similar Threats
The emergence of HOLLOWGRAPH underscores a growing trend where attackers exploit trusted collaboration tools to bypass traditional security defenses. Similar tactics have been observed, such as the use of Microsoft 365 Groups and calendar invites to deliver phishing lures. These methods exploit the inherent trust users place in familiar platforms, increasing the likelihood of successful attacks.
In response to such threats, Microsoft has enhanced its security measures. Updates to Defender for Office 365 now allow security teams to remove malicious calendar entries when performing a Hard Delete, addressing the issue of persistent malicious meeting invites.
The discovery of HOLLOWGRAPH serves as a stark reminder of the evolving landscape of cyber threats. Organizations must remain vigilant and adapt their security strategies to address these sophisticated attack vectors. Regularly updating security protocols, educating employees about emerging threats, and implementing robust monitoring systems are crucial steps in mitigating the risks associated with such advanced malware campaigns.