VMTech
Discuss a project

HollowGraph hides C2 and data theft in Microsoft 365 events dated 2050

HollowGraph hides C2 and data theft in Microsoft 365 events dated 2050

Colleagues, I’d like to draw your attention to an interesting technique from the cybersecurity space.

HollowGraph uses Microsoft 365 Calendar and the Graph API as a bidirectional channel: through events scheduled for 2050, it receives commands and exfiltrates files via attachments.

What matters:
- the traffic looks like ordinary Microsoft 365 activity;
- a separate DNS channel via AAAA queries transfers Entra ID data and application parameters;
- there is no Microsoft vulnerability here — the risk lies in a compromised account and application permissions.

Why this matters: this approach is difficult to detect without monitoring identity, OAuth applications, and Graph API activity.

What would you look at first in monitoring?

#cybersecurity #Microsoft365 #ThreatIntel #IdentitySecurity

Open analytics
On the site 2 views
min read 1 20.07.2026
On Instagram 3 views
On Instagram 1 reach
Instagram

HollowGraph hides C2 and data theft in Microsoft 365 events dated 2050

Open the post on Instagram ↗