What Happened
Part of a larger toolkit, HollowGraph uses a compromised 365 account’s calendar as a two-way dead-drop. The post New HollowGraph Malware Abuses Microsoft 365 Calendar for C&C Communication appeared first on SecurityWeek .
Why It Matters
According to Group-IB, HOLLOWGRAPH is a Windows malware linked to the Cavern framework that uses a compromised Microsoft 365 mailbox and the Microsoft Graph API to turn calendar events into a two-way dead drop for command-and-control and data exfiltration.[2][5][6] Researchers report that the malware hides operator tasking and stolen files in Outlook calendar appointments dated May 13, 2050, blending its traffic into normal Microsoft cloud communications without exploiting any Microsoft 365 or Graph vulnerability.[1][4][6] From a RealGround perspective, this highlights a broader SaaS AI risk pattern: any AI-enabled workflows or agents integrated with Microsoft 365/Graph APIs could unwittingly process or propagate attacker-controlled calendar data, so organizations should harden OAuth app governance, audit Graph-based automations, and include Microsoft 365 telemetry in AI security readiness and threat modeling. Strengthening SaaS identity controls, anomaly detection around unusual calendar events, and policy guardrails for AI agents that read or act on calendar/mail data reduces the chance that similar covert C2 or data exfiltration channels can be leveraged against AI-powered busin
RealGround Analysis
This signal maps to SaaS AI risk. Organizations using AI agents, LLM APIs, SaaS integrations, or sensitive data workflows should review whether this class of issue could create unauthorized tool execution, data leakage, weak approval gates, or unmanaged supply-chain exposure.
Recommended Actions
- Restrict AI agent tool permissions and production write paths.
- Review sensitive data access across prompts, logs, embeddings, memory, and SaaS integrations.
- Add human approval workflows for high-impact or state-changing actions.
- Run prompt injection and indirect prompt injection tests against affected workflows.
- Document the owner, control gap, and remediation deadline for this risk class.
