Signal

HollowGraph malware exploits Microsoft 365 calendar for command and control

Evidence first: scan the strongest sources, then decide whether to go deeper.

Published 2026-07-20 20:42 UTCUpdated 2026-07-21 11:55 UTC
rss
malwarecyberespionagecommand_and_controlincident_response
Trend in the last 24h
Current brief openSource links open
This current signal is open on the public brief with summary, metadata, source links, and full evidence. Pro adds compare-over-time, alerts, exports, and workflow.
No card needed for the free brief.
Evidence trail (top sources)
top sources (3 domains)domains are deduped. counts indicate coverage, not truth.
3 top sources shown
Overview

HollowGraph, a component of the Project CAV3RN cyberespionage framework, uses compromised Microsoft 365 accounts to exchange commands and data via calendar events.

Entities
MicrosoftProject CAV3RNHollowGraph
Score total
1.27
Momentum 24h
3
Posts
3
Origins
3
Source types
1
Duplicate ratio
0%
Why now
  • Recent research in mid-2026 uncovered the new HollowGraph module replacing previous C2 methods with calendar-based communication.
  • The shift to Microsoft Graph API abuse represents an evolution in malware stealth tactics within ongoing cyberespionage campaigns.
  • Heightened targeting of Israeli organizations underscores the geopolitical relevance of this threat actor's activities.
Why it matters
  • Abusing Microsoft 365 calendar events for C2 communication enables stealthy malware operations hard to detect by traditional network monitoring.
  • The modular design of Project CAV3RN allows flexible and persistent espionage capabilities against targeted organizations.
  • Understanding this novel abuse vector is critical for defenders to improve detection and incident response strategies.
LLM analysis
Topic mix: lowPromo risk: lowSource quality: high
Recurring claims
  • HollowGraph malware uses Microsoft 365 calendar events for command and control communication.
  • Project CAV3RN is a modular cyberespionage framework targeting organizations in Israel.
How sources frame it
  • SecurityWeek: neutral
  • SC Media: neutral
  • Kaspersky Securelist: neutral
This emerging malware technique highlights the increasing use of legitimate cloud services for stealthy C2 communication in cyberespionage campaigns.
All evidence
All evidence
SecurityWeek - HollowGraph malware abuses Microsoft 365 calendar for C&C
securityweek.com · securityweek.com · 2026-07-21 11:55 UTC
Kaspersky Securelist - Project CAV3RN cyberespionage framework using Outlook and DNS
securelist.com · securelist.com · 2026-07-21 08:40 UTC
Show filters & breakdown
Posts loaded: 0Publishers: 3Origin domains: 3Duplicates: -
Showing 3 / 0
Top publishers (this list)
  • securityweek.com (1)
  • scworld.com (1)
  • securelist.com (1)
Top origin domains (this list)
  • securityweek.com (1)
  • scworld.com (1)
  • securelist.com (1)