
New Malware Hides Stolen Data in Microsoft 365 Calendars
Hackers created malware that uses hijacked Microsoft 365 calendars to hide commands and stolen files, making detection extremely difficult.
Source
The Hacker News
Original headline: HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050
Plain-English summary by GetCyberRight. Read the full report at the source above.
Security researchers at Group-IB discovered a new espionage tool they named HollowGraph. This malware does something unusual: it hijacks Microsoft 365 calendar accounts and uses them to hide stolen information and receive instructions from hackers. The attackers create fake calendar events dated far in the future, specifically the year 2050, and attach stolen files to these events. Because the malware uses legitimate Microsoft systems, it blends in with normal business activity and becomes very hard to detect. This threat primarily affects businesses and organizations that use Microsoft 365 for email and calendars. If your workplace uses Microsoft 365 and you notice strange calendar invitations, especially ones dated decades in the future, this could indicate a compromise. Home users with personal Microsoft 365 accounts could also be affected if hackers gain access to their systems, though this appears to be targeting organizations for espionage purposes.
If you use Microsoft 365 for work or personal use, take these precautions:
- Check your calendar for any suspicious events, particularly ones scheduled for dates like 2050 or other far-future years that you did not create.
- Review your Microsoft 365 account activity logs to see if there are sign-ins from unfamiliar locations or devices.
- Immediately report any suspicious calendar entries to your IT department if you have one.
- Enable two-factor authentication on your Microsoft account if you have not already done so.
- Be cautious about granting calendar access to third-party applications or services. This incident demonstrates how creative hackers have become at hiding their activities inside legitimate business tools. Regularly review the permissions you have granted to apps connected to your Microsoft, Google, or Apple accounts. Remove access for any services you no longer use or do not recognize. At work, participate in any cybersecurity training your employer offers. Many successful attacks start with one person clicking a malicious link or downloading an infected file. Your awareness and caution protect not just your own data but potentially your entire organization.
Curated from trusted cybersecurity sources by GetCyberRight
Source: The Hacker NewsStay ahead of cyber threats
Get our free weekly digest. Real threats, plain language, what to do about them. No spam, ever.
More articles

Cryptocurrency Trading Platform Ostium Loses $23.7 Million in Hack
Hackers stole nearly $24 million from Ostium by compromising systems that control pricing. Cryptocurrency users should review their security practices.
2 min read
Cryptocurrency Trading Platform Loses $23.7 Million in Hack: What Crypto Users Should Know
Hackers stole millions from the Ostium trading platform by compromising systems that feed price information. This shows why crypto investments carry serious risks.
2 min read
Fake AI Projects on GitHub Are Spreading Malware to Developers and Tech Enthusiasts
Cybercriminals created nearly 7,600 fake GitHub repositories that look like legitimate AI tools but actually install malware called SmartLoader on your computer.
2 min read
Fake AI Projects on GitHub Hide Dangerous Malware: What Developers and Tech Users Should Know
Criminals created nearly 7,600 fake coding projects on GitHub that look legitimate but install malware called SmartLoader when downloaded.
2 min read