How HollowGraph Operates
On July 20, 2026, Group-IB security researchers released a study describing an implant known as HollowGraph that converts a hacked Microsoft 365 calendar into hidden communication channel. The virus communicates with attackers by abusing Microsoft’s legal Graph API, which allows communication to blend in with regular cloud activity, rather than depending on command-and-control servers. HollowGraph extracts encrypted instructions concealed inside file attachments linked to calendar events produced by the attacker once a Microsoft 365 account has been hacked. Then carries out those commands and creates its own calendar appointments with encrypted file attachments in order to exfiltrate stolen material. Every malicious calendar event is set for May 13, 2050, which is well outside of typical calendar views and lessens the possibility that the activity will be detected in order to stay hidden from the mailbox owner.
Who Is Being Targeted and Who Is Behind It
While looking into a current cyberespionage effort involving hacked Microsoft 365 systems, Group-IB came upon HollowGraph. The implant’s architecture mirrors strategies frequently used in advanced persistent threat (APT) operations that put stealth, persistence, and information gathering ahead of quick financial benefit, even though the researchers did not publicly link it to a particular threat actor. Many conventional security measures that concentrate on identifying suspect external network connections can be circumvented by HollowGraph by using Microsoft’s reliable Graph API instead of attacker-controlled infrastructure. It is crucial to keep an eye out for anomalous Graph API usage, unexpected calendar events, and other indications of account compromise in Microsoft 365 settings since the discovery reveals a rising pattern in which threat actors exploit trustworthy cloud services to hide harmful activities.
Author Notes
Group-IB Threat Intelligence Research Blog
About the Author
Carmen Estela is a Cybersecurity Research Analyst at Cyber Defense Magazine and a Women in Cybersecurity Award Candidate. She recently graduated with a Master’s of Science degree from the University of Central Florida and holds a Bachelor’s degree in Criminology from the University of Florida with certifications in Data Analytics and AI Fundamentals. She frequently speaks and volunteers at well-known industry gatherings, such as BSides Orlando and BSides Jax, where she offers her perspectives on emerging cyber trends. Carmen is committed to advancing the standards of governance, risk, and compliance within cybersecurity. She has also served as an adult protective investigator, police dispatcher, and legal intern, applying investigative skills across law enforcement, academic, and public service settings.
Reach her online at [email protected].

