Technology · 07/20/2026, 02:59 PM
New HollowGraph Malware Uses Microsoft Graph for Stealthy Attacks on Microsoft 365 Accounts
The HollowGraph malware abuses Microsoft 365 calendar functions as a covert communication channel to control attacks and steal data.
Bild: cottonbro studio / Pexels · Pexels · Pexels Lizenz: kostenlos nutzbar, Attribution freiwilligAs BleepingComputer reports (https://www.bleepingcomputer.com/news/security/new-hollowgraph-malware-uses-microsoft-graph-for-stealthy-c2-comms/), a new malware called HollowGraph has developed an unusual method to carry out attacks on Microsoft 365 accounts. The malware uses the calendar function in compromised Microsoft 365 mailboxes as a covert channel for command-and-control communication (C2).
How HollowGraph Works
The malware first infiltrates a Microsoft 365 account and then uses Microsoft Graph API access to create, read, or modify calendar events. Through these calendar appointments, the malware receives commands from the attackers and can simultaneously send back stolen data in the form of appointment details. This method allows HollowGraph to move stealthily within the data traffic, as calendar access is often considered harmless in corporate networks.
Why This Technique Is Particularly Dangerous
Using Microsoft Graph as a C2 channel is an innovative and hard-to-detect technique. Since Microsoft Graph is an official interface for accessing Microsoft 365 services, the traffic hardly raises suspicion. Additionally, attackers bypass many traditional security mechanisms designed to detect suspicious network traffic. The use of calendar events as a communication medium is also unusual and complicates analysis and detection by security solutions. Companies using Microsoft 365 are therefore especially vulnerable because the malware abuses legitimate functions.
Impact on Companies and Users
Companies using Microsoft 365 should be aware of this new threat. HollowGraph can not only exfiltrate sensitive data but also take control of user accounts, enabling further attacks. The camouflage of communication makes quick identification and containment of the infection difficult.
Recommendations for Defense
Experts advise closely monitoring the use of Microsoft Graph APIs and analyzing unusual activities related to calendar access. Furthermore, companies should regularly review and update their security policies for Microsoft 365. Multi-factor authentication (MFA) and strict access control can reduce the risk of compromise. In addition, deploying specialized security solutions that rely on behavioral analysis and anomaly detection is advisable to detect such novel attacks early.
Conclusion
The HollowGraph malware demonstrates how attackers increasingly misuse legitimate cloud services for their purposes. Integrating security mechanisms into cloud environments and raising awareness among IT personnel are crucial to fend off such threats and ensure the protection of corporate data.
Warum das wichtig ist
The HollowGraph malware demonstrates a new, hard-to-detect attack method that exploits legitimate Microsoft 365 functions. This presents companies with new challenges in detecting and defending against cyberattacks in cloud environments.
Hinweis
This article is for informational purposes only and does not constitute investment advice or a purchase recommendation. Users should adjust security measures according to their individual situation.