HOLLOWGRAPH malware abuses Microsoft 365 calendars for covert command, control, and exfiltration. Attackers hide encrypted instructions and stolen files inside future-dated calendar events. Defenders ...
Threat actors are leveraging Graph API to identify lucrative targets, then passing their access to extortion groups like ShinyHunters.
A malicious component dubbed HollowGraph uses the calendar feature in compromised Microsoft 365 mailboxes as a command-and-control channel to receive attacker commands and exfiltrate stolen data.