Skip to main content
    New Malware Hides in Microsoft 365 Calendars: How to Protect Your Business Account
    Cybersecurity
    2 min read

    New Malware Hides in Microsoft 365 Calendars: How to Protect Your Business Account

    Hackers created malware that hides stolen files in fake calendar events dated to 2050, making it hard to detect. Business users of Microsoft 365 should stay alert.

    Source

    The Hacker News

    Original headline: HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050

    Plain-English summary by GetCyberRight. Read the full report at the source above.

    Published Monday, July 20, 2026Updated Tuesday, July 21, 20262 min read
    Share:

    Security researchers discovered a new type of spying software called HollowGraph that uses Microsoft 365 calendars in a sneaky way. The malware creates calendar events dated far in the future, specifically to the year 2050, and uses those fake events to hide instructions for hackers and stolen files. Because it uses legitimate Microsoft calendar features, the malicious activity looks like normal Microsoft 365 traffic, making it very hard to detect. This threat primarily affects businesses and organizations that use Microsoft 365 for email and calendars. If hackers install this malware on a work computer, they can steal files and data while hiding their tracks in the calendar system. Home users with personal Microsoft 365 accounts face lower risk because this type of sophisticated espionage malware typically targets organizations, not individual families. However, anyone using Microsoft 365 should be aware that calendar systems can be abused.

    If you use Microsoft 365 at work, stay alert for unusual activity.

    1. Check your calendar occasionally for strange events, especially any scheduled far in the future like

    2. Report any suspicious calendar entries to your IT department immediately.

    Stay one step ahead of scammers

    Weekly cybersecurity briefings for families. No spam, just the threats that matter and what to do about them.

  1. Never click on attachments or links in calendar invitations from people you do not know.

  2. Be cautious about granting calendar permissions to unfamiliar applications or services.

  3. If you manage Microsoft 365 for your organization, ask your IT security team if they are monitoring for unusual calendar activity. This incident shows that hackers constantly find creative ways to abuse legitimate tools and services. The best protection is basic security hygiene across all your accounts. Use strong, unique passwords for every account. Enable two factor authentication wherever possible. Keep your computer and all software updated. Be skeptical of unexpected emails, calendar invitations, or file sharing requests, even if they appear to come from colleagues. When in doubt, verify through a separate communication method before clicking or downloading anything.

  4. Protect Yourself

    Use our Cyber Threat Radar to check if you're affected and take action.

    Found this useful?

    Share it with someone who could use a heads-up.

    Share:

    Curated from trusted cybersecurity sources by GetCyberRight

    Source: The Hacker News

    Discussion

    0

    Sign in to join the discussion.

    Stay ahead of cyber threats

    Get our free weekly digest. Real threats, plain language, what to do about them. No spam, ever.