Watch out - that Microsoft Calendar invite dated 2050 could be hiding stolen files and worse
Date:
Tue, 21 Jul 2026 16:15:00 +0000
Description:
Check your calendars for entries far into the future - especially if you're
an Israeli entity.
FULL STORY ======================================================================Copy link Facebook X Whatsapp Reddit Pinterest Flipboard Threads Email Share this article 0 Join the conversation Follow us Add us as a preferred source on Google Newsletter Subscribe to our newsletter GroupIB discovers HollowGraph malware targeting Israeli entities, exfiltrating files via Microsoft Graph
API Operators hide instructions in future calendar entries, then attach encrypted stolen data to events At least 12 systems were compromised;
overlaps with Lyceum noted but attribution remains lowconfidence Cybercriminals have found a way to communicate with the malware installed on victim devices through compromised Microsoft Calendar apps, experts have warned.
Security researchers at Group-IB have detailed a newly discovered piece of malware called HollowGraph designed to exfiltrate sensitive files from compromised devices. What makes the malware stand out is the way it communicates with its operators. The best way to spot hidden malware is to monitor the traffic flowing in and out of a device, which is why cybercriminals try their best to hide this traffic, or blend it with another, legitimate one. In that respect, HollowGraph is unique because it abuses Microsoft Graph API and a compromised Microsoft 365 mailbox calendar. Latest Videos From Watch full video here: A dozen victims After landing on a device and compromising the Microsoft 365 account, HollowGraph uses that accounts permissions to access Microsoft Graph. Operators create calendar entries containing instructions and place them far into the future (in the year 2050) to avoid being spotted. After acting on the instructions and harvesting valuable information, the malware exfiltrates it through the same channel.
Instead of uploading files to a suspicious server, HollowGraph attaches encrypted stolen data to calendar events and sends it through Microsoft
Graph. For defenders, all of this traffic seems legitimate and usually flies under their radars. You may like Hackers are establishing persistence in hospitality and hotels by posing as guests with poisoned ZIP archives, but no one knows what their plan is New cyber scam abuses Microsoft Teams to steal your data Experts warn hackers are hiding malware inside Google's own ad systems here's what we know
So far, all of the victims are Israeli entities, Group-IB said. The researchers identified at least 12 compromised systems, three of which were still actively communicating with the attackers infrastructure during the investigation.
The researchers did not attribute the attack to any known threat actor, but hinted at a potential. They identified technical similarities in command structures and plugin mechanisms between HollowGraphs framework, Cavern, and
a .NET backdoor used by Lyceum (an Iranian-nexus threat actor associated with OilRig). However, Group-IB explicitly emphasizes that these overlaps are not distinct enough, so they assess this link with low confidence. Are you a pro? Subscribe to our newsletter Sign up to the TechRadar Pro newsletter to get
all the top news, opinion, features and guidance your business needs to succeed! Contact me with news and offers from other Future brands Receive email from us on behalf of our trusted partners or sponsors By submitting
your information you agree to the Terms & Conditions and Privacy Policy and are aged 16 or over. The best antivirus for all budgets Our top picks, based on real-world testing and comparisons
Read our full guide to the best antivirus 1. Best overall: Bitdefender Total Security 2. Best for families: Norton 360 with LifeLock 3. Best for mobile: McAfee Mobile Security Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.
======================================================================
Link to news story:
https://www.techradar.com/pro/security/watch-out-that-microsoft-calendar-invit e-dated-2050-could-be-hiding-stolen-files-and-worse
--- Mystic BBS v1.12 A49 (Linux/64)
* Origin: tqwNet Technology News (1337:1/100)