PulseAugur
EN
LIVE 16:08:25

HOLLOWGRAPH malware uses Microsoft 365 calendars for covert data exfiltration

A new malware campaign, dubbed HOLLOWGRAPH, is exploiting Microsoft 365 calendars to exfiltrate data and receive commands. The malware embeds malicious instructions within calendar appointments set for the year 2050. It then leverages Microsoft's own cloud infrastructure, specifically Exchange Online, to communicate with its command-and-control servers. This technique allows the malware to blend in with legitimate network traffic, making it harder to detect. AI

IMPACT This technique highlights a new avenue for stealthy data exfiltration, potentially impacting security strategies for cloud-based productivity tools.

RANK_REASON The cluster describes a novel malware technique exploiting a common productivity suite, which falls under the 'tool' category as it details a specific application of malicious software.

Read on Mastodon — mastodon.social →

AI-generated summary · Google Gemini · from 2 sources. How we write summaries →

HOLLOWGRAPH malware uses Microsoft 365 calendars for covert data exfiltration

COVERAGE [2]

  1. The Register — AI TIER_1 English(EN) ·

    Microsoft 365 calendars become spy drop boxes in HOLLOWGRAPH campaign

    Malware hides commands in appointments set for 2050 and uses Redmond's own cloud to phone home

  2. Mastodon — mastodon.social TIER_1 English(EN) · [email protected] ·

    🤖 Microsoft 365 calendars become spy drop boxes in HOLLOWGRAPH campaign 📝 Microsoft 365 calendars have... https://www. theregister.com/security/2026/ 07/20/micr

    🤖 Microsoft 365 calendars become spy drop boxes in HOLLOWGRAPH campaign 📝 Microsoft 365 calendars have... https://www. theregister.com/security/2026/ 07/20/microsoft-365-calendars-become-spy-drop-boxes-in-hollowgraph-campaign/5274982 📰 www.theregister.com - Articles # AI # Malwar…