Malware Turns Microsoft 365 Calendar Into Covert Attack VectorKey Takeaways HOLLOWGRAPH malware abuses Microsoft 365 calendars for covert command, control, and exfiltration. Attackers hide encrypted instructions and stolen files inside future-dated calendar events. Security researchers at Group-IB have uncovered a Windows malware strain that turns Microsoft 365 calendars into covert channels for receiving commands and stealing files from targeted organizations. The malware component, dubbed HOLLOWGRAPH, abuses the Microsoft Graph API and a compromised Microsoft 365 account to conceal command-and-control activity within legitimate cloud communications. Attackers create calendar events containing encrypted instructions while HOLLOWGRAPH uploads stolen files as attachments to separate events.