Beware: That Microsoft Calendar Invitation Dated 2050 Could Hide Stolen Files and Worse



  • Group-IB discovers HollowGraph malware targeting Israeli entities and extracting files via Microsoft Graph API
  • Operators hide instructions in future calendar entries and then attach encrypted stolen data to events
  • At least 12 systems were compromised; Overlap is observed with Lyceum, but attribution remains low confidence.

Experts warned that cybercriminals have found a way to communicate with malware installed on victims’ devices through compromised Microsoft Calendar applications.

Security researchers at Group-IB have detailed a recently discovered malware called HollowGraph, designed to exfiltrate sensitive files from compromised devices.

Leave a Comment

Your email address will not be published. Required fields are marked *