Microsoft 365 calendars dated May 13, 2050 hide HOLLOWGRAPH commands and stolen files
Group-IB says espionage malware uses trusted Microsoft Graph traffic to “calendar” its control and exfiltration.

Researchers at Group-IB say they found HOLLOWGRAPH, an espionage malware component that hides encrypted instructions in Microsoft 365 calendar events dated May 13, 2050. For decision-makers, it is a reminder that “legitimate cloud activity” can be the cleanest disguise in the room.
Microsoft 365 calendars have become espionage drop boxes, with Group-IB reporting a malware component it calls HOLLOWGRAPH that stashes encrypted commands and stolen files inside calendar events dated May 13, 2050. The trick is not just the far-future timestamp. It is the way HOLLOWGRAPH moves through Microsoft 365 itself, using calendar events as its internal inbox and collecting the results later, in other appointments, for operators to retrieve.
The core mechanism is even more unsettling: instead of classic command-and-control, HOLLOWGRAPH swaps attacker-controlled infrastructure for something less suspicious, a compromised Microsoft 365 calendar. It reads calendar events, pulls encrypted tasking from them, and then drops stolen files into new appointments that keep the whole operation looking like normal Microsoft Graph API usage. Every event created by HOLLOWGRAPH is dated May 13, 2050, an “otherwise empty corner” of the calendar where encrypted attachments may look less like an obvious security incident.
For security leaders and the boards that oversee enterprise risk, this matters because it flips the usual detection logic. Many perimeter defenses, email filters, and network monitoring setups are built around the assumption that malware must “call home” to somewhere outside the trusted cloud boundary. Here, Group-IB says HOLLOWGRAPH does not exploit Microsoft Graph as a vulnerability so much as it blends into Graph. The malware wraps its communications inside legitimate Microsoft 365 application requests to the cloud. That means defenders staring at raw network behavior may see something that resembles ordinary tenant activity rather than clear signs of an attacker reaching out.
Group-IB describes HOLLOWGRAPH as relatively lean. It does little more than fetch instructions from one calendar event, store stolen files in another appointment, and periodically retrieve fresh Entra ID credentials over a DNS tunneling channel so the Graph-based communications keep working. In plain English: it uses the calendar as the command and file transfer layer, and it uses DNS tunneling as a way to refresh cloud authentication credentials without tipping its hand through conventional infrastructure. If your org assumes “Graph traffic equals safe usage,” HOLLOWGRAPH is designed to stress exactly that assumption.
There is also the strategic attribution piece, which is where execs should pay attention even if you are not an incident response specialist. Group-IB linked the malware to the Cavern framework with high confidence by finding matching command formats and other implementation details. It also spotted similarities with the Iranian-linked espionage group Lyceum, but stopped short of pinning the operation on that crew, saying the connection had only low confidence. Put differently, the evidence points toward a focused, evolving espionage playbook rather than an opportunistic crime spree.
The campaign appears narrowly targeted, not mass infection. Group-IB identified 12 infected systems, and only three of them communicated with the compromised mailbox during the observation period. It also reported that the compromised mailbox used for command-and-control belonged to an Israeli organization, that malware samples were uploaded from Israel, and that the evidence points to a focused espionage operation rather than a broad smash-and-grab. For leaders, the second-order implication is straightforward: “low volume” does not mean “low risk.” Small footprints can still represent serious access and long dwell time.
Crucially, Group-IB says HOLLOWGRAPH does not exploit a flaw in Microsoft 365 or Microsoft Graph. The malware instead abuses services that are already trusted inside most organizations, making the activity far less conspicuous than malware calling home to attacker-controlled infrastructure. That framing has regulatory and governance echoes. Regulators and auditors increasingly expect controls that account for misuse of legitimate tooling, not just blocking suspicious domains. When trusted systems become the attacker’s camouflage, you need detection and response strategies that can look through “valid API traffic” and still answer: why is this event being created, accessed, or attached in a way that does not match business context?
So what is at stake for decision-makers beyond this one case? If attackers can hide inside Microsoft 365 calendars through the Microsoft Graph API, then cloud trust models become part of the threat surface, not a shield. The strategic challenge is to ensure that your security program can detect malicious use patterns inside normal productivity workflows, while your compliance program can justify that approach. HOLLOWGRAPH is a highly targeted espionage threat, Group-IB wrote, and its method is a blueprint for a world where “legitimate traffic” is no longer a guarantee. For CISOs, risk committees, and anyone who signs off on security budgets, the message is clear: you cannot defend only against the obvious exits. You also have to watch how attackers try to turn the building into the hiding place.
This story's Key Insights and Take-aways are locked.
Create a free account to unlock Executive Actions for one credit.
Register to UnlockAlways free for Executives Club members. Join the Club
More in Technology

EU slaps AliExpress with record $625M DSA fine for counterfeit and safety failures
The European Commission says AliExpress did not mitigate illegal, unsafe, or counterfeit risks, and that delay is now expensive.
Google’s AI search is pulling time away from the open web, operators say
As more answers move inside Google, website operators argue the open web loses traffic and incentives to publish.

Anthropic wins final approval for $1.5B copyright settlement, but AI training fight remains
A court approved a landmark $1.5B settlement tied to copyrighted works. The case closes one dispute, not the larger rulebook question.
