- Group-IB discovers HollowGraph malware targeting Israeli entities and extracting files via Microsoft Graph API
- Operators hide instructions in future calendar entries and then attach encrypted stolen data to events
- At least 12 systems were compromised; Overlap is observed with Lyceum, but attribution remains low confidence.
Experts warned that cybercriminals have found a way to communicate with malware installed on victims’ devices through compromised Microsoft Calendar applications.
Security researchers at Group-IB have detailed a recently discovered malware called HollowGraph, designed to exfiltrate sensitive files from compromised devices.
What sets malware apart is the way it communicates with its operators. The best way to detect hidden malware is to monitor the traffic going in and out of a device, which is why cybercriminals go to great lengths to hide this traffic or combine it with legitimate traffic. In that sense, HollowGraph is unique because it abuses the Microsoft Graph API and a compromised Microsoft 365 mailbox calendar.
a dozen victims
After landing on a device and compromising the Microsoft 365 account, HollowGraph uses that account’s permissions to access Microsoft Graph. Operators create calendar entries containing instructions and place them in the distant future (in the year 2050) to avoid discovery. After following the instructions and collecting valuable information, the malware leaks it through the same channel.
Instead of uploading files to a suspicious server, HollowGraph attaches encrypted stolen data to calendar events and sends them through Microsoft Graph. To defenders, all this traffic appears legitimate and typically goes unnoticed.
So far, all victims are Israeli entities, Group-IB said. Researchers identified at least 12 compromised systems, three of which were still actively communicating with the attackers’ infrastructure during the investigation.
Researchers did not attribute the attack to any known threat actors, but hinted at a potential. They identified technical similarities in command structures and plugin mechanisms between the HollowGraph framework, Cavern, and a .NET backdoor used by Lyceum (an Iranian nexus threat actor associated with OilRig). However, Group IB explicitly emphasizes that these overlaps are not distinct enough, so they evaluate this link with low confidence.
The best antivirus for all budgets
Follow TechRadar on Google News and add us as a preferred source to receive news, reviews and opinions from our experts in your feeds.




