The record
Written from the 2 reports below. Nothing here is unsourced.
- Security researchers at Group-IB disclosed HollowGraph, a new espionage malware module that hijacks Microsoft 365 calendar features to hide command-and-control traffic and exfiltrated data.
- The implant creates calendar events dated to the year 2050 to evade routine log review and is believed to be linked to an Iranian threat actor targeting Israeli organizations.
- Coverage comes from two cybersecurity outlets: The Hacker News (neutral) and BleepingComputer (alarmist), both relaying essentially the same technical findings with no substantive editorial divergence.
- What makes HollowGraph notable is its living-off-the-land approach inside a widely trusted productivity suite, avoiding traditional C2 infrastructure except for a domain (cloudlanecdn.com) used for initial configuration delivery.
- No public exploit or proof-of-concept has been reported, and no Microsoft vulnerability is abused—rather, OAuth and Graph API permissions are misused.
- Organizations worldwide using Microsoft 365 are potentially exposed, but attribution and victim scale remain uncertain.
- Analysts recommend hunting for far-future calendar events, auditing client-credential OAuth apps, and monitoring for the identified IOC domain.
What to watch next
- Hunt M365 audit logs for calendar events dated 2050 or with bare GUID subjects.
- Audit and restrict OAuth client-credential apps registered in Entra ID.
- Block and monitor DNS for the cloudlanecdn.com domain and AAAA tunneling patterns.
- Review Microsoft Graph mailbox activity for application-driven calendar changes.
What changed2
Every report on this story, newest first. Times are when each outlet published.
BleepingComputer[1]
New HollowGraph malware uses Microsoft Graph for stealthy C2 commsThe Hacker News[2]
HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050
Why it matters4
Who is affected first and what likely follows, with a direction and a horizon. Extracted from the reports, never invented.
- Israeli organizations using Microsoft 365 espionage risk· weeks
- Microsoft 365 / Entra ID tenants audit and remediation required· days
- Security operations teams increased monitoring burden· immediate
- Microsoft reputation and abuse scrutiny· weeks
Coverage2
Filed from India ×1, United States ×1
Named Israel · Iran · Entra ID · HollowGraph · Microsoft · Microsoft 365 · Microsoft Graph API · Cavern · Cavern Manticore · Check Point · cloudlanecdn.com · Group-IB
The 2 reports are listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.

