Technology · 07/20/2026, 02:59 PM

New HollowGraph Malware Uses Microsoft Graph for Stealthy Attacks on Microsoft 365 Accounts

The HollowGraph malware abuses Microsoft 365 calendar functions as a covert communication channel to control attacks and steal data.

New HollowGraph Malware Uses Microsoft Graph for Stealthy Attacks on Microsoft 365 AccountsBild: cottonbro studio / Pexels · Pexels · Pexels Lizenz: kostenlos nutzbar, Attribution freiwillig
Cybersecurity-Software & SchutztoolsPassende Tools für Sicherheit, VPN, Passwortverwaltung, Backup und Malware-Schutz.Security-Tools ansehenSoftware & digitale ToolsEmpfohlene Software-, SaaS- und Security-Angebote über Avangate/Verifone oder Direktpartner.Software-Angebote ansehenAnzeige / Affiliate möglich. Für dich entstehen keine Mehrkosten.

As BleepingComputer reports (https://www.bleepingcomputer.com/news/security/new-hollowgraph-malware-uses-microsoft-graph-for-stealthy-c2-comms/), a new malware called HollowGraph has developed an unusual method to carry out attacks on Microsoft 365 accounts. The malware uses the calendar function in compromised Microsoft 365 mailboxes as a covert channel for command-and-control communication (C2).

How HollowGraph Works

The malware first infiltrates a Microsoft 365 account and then uses Microsoft Graph API access to create, read, or modify calendar events. Through these calendar appointments, the malware receives commands from the attackers and can simultaneously send back stolen data in the form of appointment details. This method allows HollowGraph to move stealthily within the data traffic, as calendar access is often considered harmless in corporate networks.

Why This Technique Is Particularly Dangerous

Using Microsoft Graph as a C2 channel is an innovative and hard-to-detect technique. Since Microsoft Graph is an official interface for accessing Microsoft 365 services, the traffic hardly raises suspicion. Additionally, attackers bypass many traditional security mechanisms designed to detect suspicious network traffic. The use of calendar events as a communication medium is also unusual and complicates analysis and detection by security solutions. Companies using Microsoft 365 are therefore especially vulnerable because the malware abuses legitimate functions.

Impact on Companies and Users

Companies using Microsoft 365 should be aware of this new threat. HollowGraph can not only exfiltrate sensitive data but also take control of user accounts, enabling further attacks. The camouflage of communication makes quick identification and containment of the infection difficult.

Recommendations for Defense

Experts advise closely monitoring the use of Microsoft Graph APIs and analyzing unusual activities related to calendar access. Furthermore, companies should regularly review and update their security policies for Microsoft 365. Multi-factor authentication (MFA) and strict access control can reduce the risk of compromise. In addition, deploying specialized security solutions that rely on behavioral analysis and anomaly detection is advisable to detect such novel attacks early.

Conclusion

The HollowGraph malware demonstrates how attackers increasingly misuse legitimate cloud services for their purposes. Integrating security mechanisms into cloud environments and raising awareness among IT personnel are crucial to fend off such threats and ensure the protection of corporate data.

Cybersecurity-Software & SchutztoolsPassende Tools für Sicherheit, VPN, Passwortverwaltung, Backup und Malware-Schutz.Security-Tools ansehenSoftware & digitale ToolsEmpfohlene Software-, SaaS- und Security-Angebote über Avangate/Verifone oder Direktpartner.Software-Angebote ansehenAnzeige / Affiliate möglich. Für dich entstehen keine Mehrkosten.

Warum das wichtig ist

The HollowGraph malware demonstrates a new, hard-to-detect attack method that exploits legitimate Microsoft 365 functions. This presents companies with new challenges in detecting and defending against cyberattacks in cloud environments.

Hinweis

This article is for informational purposes only and does not constitute investment advice or a purchase recommendation. Users should adjust security measures according to their individual situation.

Quellen