← Back to feed
malware threats2 sources · 6d ago

HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050

Group-IB researchers identified a new HollowGraph malware module that abuses Microsoft 365 calendar features as a covert command-and-control channel, likely linked to an Iranian threat actor targeting Israeli organizations.

AffectedIsraelIran Entra ID HollowGraph Israel Microsoft Microsoft 365 Microsoft Graph API Cavern Cavern Manticore Check Point cloudlanecdn.com Group-IB Iran
2 outlets · 2 origins · Balanced
India × 1United States × 1

Through the Reader lens — Security researchers at Group-IB disclosed HollowGraph, a new espionage malware module that hijacks Microsoft 365 calendar features to hide command-and-control traffic and exfiltrated data. The implant creates calendar events dated to the year 2050 to evade routine log review and is believed to be linked to an Iranian threat actor targeting Israeli organizations. Coverage comes from two cybersecurity outlets: The Hacker News (neutral) and BleepingComputer (alarmist), both relaying essentially the same technical findings with no substantive editorial divergence. What makes HollowGraph notable is its living-off-the-land approach inside a widely trusted productivity suite, avoiding traditional C2 infrastructure except for a domain (cloudlanecdn.com) used for initial configuration delivery. No public exploit or proof-of-concept has been reported, and no Microsoft vulnerability is abused—rather, OAuth and Graph API permissions are misused. Organizations worldwide using Microsoft 365 are potentially exposed, but attribution and victim scale remain uncertain. Analysts recommend hunting for far-future calendar events, auditing client-credential OAuth apps, and monitoring for the identified IOC domain.

What to watch next

  • Hunt M365 audit logs for calendar events dated 2050 or with bare GUID subjects.
  • Audit and restrict OAuth client-credential apps registered in Entra ID.
  • Block and monitor DNS for the cloudlanecdn.com domain and AAAA tunneling patterns.
  • Review Microsoft Graph mailbox activity for application-driven calendar changes.

Perspectives

The story's competing narratives, side by side — grouped by stance, with every outlet's origin and affiliation visible.

Group-IB Researchers / The Hacker News, BleepingComputerTechnical disclosure of Iranian-linked malware targeting Israel

Group-IB uncovered HollowGraph, a malware module that abuses Microsoft 365 calendar features (events dated to 2050) as a covert C2 and exfiltration channel; both outlets report it is likely tied to an Iranian threat actor targeting Israeli organizations and provide IOCs including the cloudlanecdn.com domain.

The Hacker NewsBleepingComputer
Neutral reportingNo distinct framing beyond research dissemination

The Hacker News neutrally relays Group-IB’s technical findings on HollowGraph’s calendar-based C2 and data exfiltration, without editorializing on attribution beyond ‘likely linked to Iran’.

The Hacker News

What to expect

First-order impacts with their likely second-order effects — direction and horizon per node.

  • Israeli organizations using Microsoft 365 espionage risk · weeks
  • Microsoft 365 / Entra ID tenants audit and remediation required · days
  • Security operations teams increased monitoring burden · immediate
  • Microsoft reputation and abuse scrutiny · weeks

Sources (2)

HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050 — Prism