HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050
Group-IB researchers identified a new HollowGraph malware module that abuses Microsoft 365 calendar features as a covert command-and-control channel, likely linked to an Iranian threat actor targeting Israeli organizations.

Through the Reader lens — Security researchers at Group-IB disclosed HollowGraph, a new espionage malware module that hijacks Microsoft 365 calendar features to hide command-and-control traffic and exfiltrated data. The implant creates calendar events dated to the year 2050 to evade routine log review and is believed to be linked to an Iranian threat actor targeting Israeli organizations. Coverage comes from two cybersecurity outlets: The Hacker News (neutral) and BleepingComputer (alarmist), both relaying essentially the same technical findings with no substantive editorial divergence. What makes HollowGraph notable is its living-off-the-land approach inside a widely trusted productivity suite, avoiding traditional C2 infrastructure except for a domain (cloudlanecdn.com) used for initial configuration delivery. No public exploit or proof-of-concept has been reported, and no Microsoft vulnerability is abused—rather, OAuth and Graph API permissions are misused. Organizations worldwide using Microsoft 365 are potentially exposed, but attribution and victim scale remain uncertain. Analysts recommend hunting for far-future calendar events, auditing client-credential OAuth apps, and monitoring for the identified IOC domain.
What to watch next
- Hunt M365 audit logs for calendar events dated 2050 or with bare GUID subjects.
- Audit and restrict OAuth client-credential apps registered in Entra ID.
- Block and monitor DNS for the cloudlanecdn.com domain and AAAA tunneling patterns.
- Review Microsoft Graph mailbox activity for application-driven calendar changes.
