CyberSecurity News
HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050
AI summary
Researchers have discovered a new type of malware, called HollowGraph, which uses a compromised Microsoft 365 calendar to communicate with its operators and exfiltrate stolen data. The malware hides operator instructions and stolen files as attachments on calendar events scheduled for the year 2050. This approach allows the malware to blend in with legitimate traffic by utilizing the Microsoft Graph API. As a result, the malicious activity is disguised to appear normal. The HollowGraph malware was identified by Group-IB, a cybersecurity firm. The use of legitimate API traffic makes it difficult to distinguish the malicious activity from normal traffic.
This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.

