
New Malware Hides in Microsoft 365 Calendars: How to Protect Your Business Account
Hackers created malware that hides stolen files in fake calendar events dated to 2050, making it hard to detect. Business users of Microsoft 365 should stay alert.
Source
The Hacker News
Original headline: HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050
Plain-English summary by GetCyberRight. Read the full report at the source above.
Security researchers discovered a new type of spying software called HollowGraph that uses Microsoft 365 calendars in a sneaky way. The malware creates calendar events dated far in the future, specifically to the year 2050, and uses those fake events to hide instructions for hackers and stolen files. Because it uses legitimate Microsoft calendar features, the malicious activity looks like normal Microsoft 365 traffic, making it very hard to detect. This threat primarily affects businesses and organizations that use Microsoft 365 for email and calendars. If hackers install this malware on a work computer, they can steal files and data while hiding their tracks in the calendar system. Home users with personal Microsoft 365 accounts face lower risk because this type of sophisticated espionage malware typically targets organizations, not individual families. However, anyone using Microsoft 365 should be aware that calendar systems can be abused.
If you use Microsoft 365 at work, stay alert for unusual activity.
Check your calendar occasionally for strange events, especially any scheduled far in the future like
Report any suspicious calendar entries to your IT department immediately.
Stay one step ahead of scammers
Weekly cybersecurity briefings for families. No spam, just the threats that matter and what to do about them.
Never click on attachments or links in calendar invitations from people you do not know.
Be cautious about granting calendar permissions to unfamiliar applications or services.
If you manage Microsoft 365 for your organization, ask your IT security team if they are monitoring for unusual calendar activity. This incident shows that hackers constantly find creative ways to abuse legitimate tools and services. The best protection is basic security hygiene across all your accounts. Use strong, unique passwords for every account. Enable two factor authentication wherever possible. Keep your computer and all software updated. Be skeptical of unexpected emails, calendar invitations, or file sharing requests, even if they appear to come from colleagues. When in doubt, verify through a separate communication method before clicking or downloading anything.
Curated from trusted cybersecurity sources by GetCyberRight
Source: The Hacker NewsStay ahead of cyber threats
Get our free weekly digest. Real threats, plain language, what to do about them. No spam, ever.
More articles

Cryptocurrency Trading Platform Ostium Loses $23.7 Million in Hack
Hackers stole nearly $24 million from Ostium by compromising systems that control pricing. Cryptocurrency users should review their security practices.
2 min read
Cryptocurrency Trading Platform Loses $23.7 Million in Hack: What Crypto Users Should Know
Hackers stole millions from the Ostium trading platform by compromising systems that feed price information. This shows why crypto investments carry serious risks.
2 min read
Fake AI Projects on GitHub Are Spreading Malware to Developers and Tech Enthusiasts
Cybercriminals created nearly 7,600 fake GitHub repositories that look like legitimate AI tools but actually install malware called SmartLoader on your computer.
2 min read
Fake AI Projects on GitHub Hide Dangerous Malware: What Developers and Tech Users Should Know
Criminals created nearly 7,600 fake coding projects on GitHub that look legitimate but install malware called SmartLoader when downloaded.
2 min read