Skip to main content
    New Malware Hides Stolen Data in Microsoft 365 Calendars
    Cybersecurity
    2 min read

    New Malware Hides Stolen Data in Microsoft 365 Calendars

    Hackers created malware that uses hijacked Microsoft 365 calendars to hide commands and stolen files, making detection extremely difficult.

    Source

    The Hacker News

    Original headline: HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050

    Plain-English summary by GetCyberRight. Read the full report at the source above.

    Published Monday, July 20, 2026Updated Tuesday, July 21, 20262 min read
    Share:

    Security researchers at Group-IB discovered a new espionage tool they named HollowGraph. This malware does something unusual: it hijacks Microsoft 365 calendar accounts and uses them to hide stolen information and receive instructions from hackers. The attackers create fake calendar events dated far in the future, specifically the year 2050, and attach stolen files to these events. Because the malware uses legitimate Microsoft systems, it blends in with normal business activity and becomes very hard to detect. This threat primarily affects businesses and organizations that use Microsoft 365 for email and calendars. If your workplace uses Microsoft 365 and you notice strange calendar invitations, especially ones dated decades in the future, this could indicate a compromise. Home users with personal Microsoft 365 accounts could also be affected if hackers gain access to their systems, though this appears to be targeting organizations for espionage purposes.

    If you use Microsoft 365 for work or personal use, take these precautions:

    1. Check your calendar for any suspicious events, particularly ones scheduled for dates like 2050 or other far-future years that you did not create.
    2. Review your Microsoft 365 account activity logs to see if there are sign-ins from unfamiliar locations or devices.
    3. Immediately report any suspicious calendar entries to your IT department if you have one.
    4. Enable two-factor authentication on your Microsoft account if you have not already done so.
    5. Be cautious about granting calendar access to third-party applications or services. This incident demonstrates how creative hackers have become at hiding their activities inside legitimate business tools. Regularly review the permissions you have granted to apps connected to your Microsoft, Google, or Apple accounts. Remove access for any services you no longer use or do not recognize. At work, participate in any cybersecurity training your employer offers. Many successful attacks start with one person clicking a malicious link or downloading an infected file. Your awareness and caution protect not just your own data but potentially your entire organization.

    Protect Yourself

    Use our Cyber Threat Radar to check if you're affected and take action.

    Found this useful?

    Share it with someone who could use a heads-up.

    Share:

    Curated from trusted cybersecurity sources by GetCyberRight

    Source: The Hacker News

    Discussion

    0

    Sign in to join the discussion.

    Stay ahead of cyber threats

    Get our free weekly digest. Real threats, plain language, what to do about them. No spam, ever.