Iranian-Linked HOLLOWGRAPH Malware Turns M365 Calendar Events Into Malicious Commands

Group-IB linked the Windows implant to the Iranian-nexus Cavern framework and found encrypted tasking hidden inside calendar events dated to May 2050.

Published on Jul 20, 2026
Iranian-Linked HOLLOWGRAPH Malware Turns M365 Calendar Events Into Malicious Commands

Security researchers have discovered a Windows malware, dubbed HOLLOWGRAPH, that abuses Microsoft’s Graph API to turn a compromised Microsoft 365 mailbox calendar into a covert two-way command-and-control channel.

The report by Group-IB threat intelligence, published earlier today, attributes the implant with high confidence to the Cavern backdoor framework, previously documented by Check Point as an Iranian-nexus modular tool.

HOLLOWGRAPH supports just two commands, get and send. Both run through Microsoft’s cloud infrastructure.

Operators plant tasking in the compromised mailbox’s calendar as events, the implant exfiltrates encrypted files by creating its own events with the stolen data attached. Every event is dated 13 May 2050 to keep the malicious entries out of the mailbox owner’s line of sight.

A separate channel handles credential renewal. The malware runs DNS tunneling over IPv6 AAAA record queries against the attacker-controlled domain cloudlanecdn[.]com, using the responses to refresh the Microsoft Entra ID credentials the implant authenticates with.

Communications through the Graph API are protected with hybrid RSA-OAEP and AES-256-GCM encryption, with separate RSA key pairs for individual directions so tasking and exfiltration stay cryptographically independent.

A Small, Selective Campaign With Israeli Focus

Group-IB identified 12 systems carrying the implant, with roughly three actively communicating with the attacker during the observation period between June 3 and July 9.

The compromised mailbox used for command-and-control (C2) belongs to an Israeli organization, and the malware samples themselves were uploaded from Israel, suggesting a targeted operation aimed at Israeli entities rather than broad opportunistic activity.

Beyond the Cavern link, Group-IB stopped short of firmer attribution. The report notes several technical overlaps with malware previously tied to Lyceum, an Iranian-nexus sub-group of OilRig, but at low confidence.

Javier Castillo, a Group-IB threat researcher, described HOLLOWGRAPH as “an advanced and highly targeted espionage threat.”

Defenders can hunt for far-future calendar events with unusual subject formats, application-created rather than user-created calendar operations, and unusual AAAA-record DNS query activity. Group-IB recommended Conditional Access policies, credential rotation, and DNS filtering as core controls.

This field is for validation purposes and should be left unchanged.

FREE NEWSLETTER

Cyber Weekly

Get curated cybersecurity news, threats and insights delivered free every Thursday.

Written By Written By
Alessandro Mascellino
Alessandro Mascellino Cybersecurity Reporter

Alessandro Mascellino is a British-Italian freelance journalist specializing in technology and gaming. He has contributed to several publications, including Wired, The Independent, and Android Police. By day, he works as a journalist. By night, he co-manages a game studio that creates narrative games.