Return to Threats

HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050

thehackernews.com 2026-07-20 SaaS AI risk High

What Happened

A newly discovered espionage implant has been using a hijacked Microsoft 365 calendar as its command channel, planting operator instructions and smuggling out stolen files as attachments on calendar events dated to the year 2050. Group-IB, which named the malware HollowGraph, says the approach moves tasking and stolen data through legitimate Microsoft Graph API traffic, so the activity looks

Why It Matters

Per the report, HollowGraph is an espionage-focused Windows implant that uses a compromised Microsoft 365 account and the Microsoft Graph API to hide command-and-control and data exfiltration inside calendar events dated May 13, 2050, with GUID-like subjects and File{n}.txt attachments.[1][2][3] The campaign does not exploit a Microsoft vulnerability, but instead abuses normal Graph API functionality and SaaS identity/App permissions, making it hard to distinguish from legitimate cloud traffic.[1][3][6] From a RealGround perspective, this illustrates a significant SaaS AI risk: Graph-integrated AI agents or automation that trust calendar and mailbox data can be silently abused as part of the same attack surface, especially if they run with broad OAuth scopes or client-credential flows against Microsoft 365 APIs. Organizations should incorporate continuous red teaming of their SaaS/Graph-integrated AI agents, including hunting for anomalous far-future calendar events, application-driven calendar changes, and over-privileged OAuth apps, and tighten Entra ID controls (Conditional Access, secret creation alerts, token anomaly detection) around any AI or automation that uses Microsoft G

Healthcare Fintech SaaS SMB AI startups

RealGround Analysis

This signal maps to SaaS AI risk. Organizations using AI agents, LLM APIs, SaaS integrations, or sensitive data workflows should review whether this class of issue could create unauthorized tool execution, data leakage, weak approval gates, or unmanaged supply-chain exposure.

Recommended Actions

  • Restrict AI agent tool permissions and production write paths.
  • Review sensitive data access across prompts, logs, embeddings, memory, and SaaS integrations.
  • Add human approval workflows for high-impact or state-changing actions.
  • Run prompt injection and indirect prompt injection tests against affected workflows.
  • Document the owner, control gap, and remediation deadline for this risk class.

Source

https://thehackernews.com/2026/07/hollowgraph-malware-hides-c2-and-stolen.html

Talk to AI CISO