Most businesses assume that suspicious activity comes from suspicious places. Unfortunately, modern cybercriminals increasingly abuse trusted platforms that organizations use every day. A recently discovered malware campaign, known as HOLLOWGRAPH, demonstrates exactly how attackers are evolving their tactics by hiding command-and-control communications (the secret check-ins malware uses to receive instructions and send back stolen data) inside Microsoft 365 calendar events.
In short: attackers are hiding instructions inside calendar invites on Microsoft 365, a place most security tools aren’t trained to suspect.
Rather than communicating with traditional malicious servers, the malware uses a compromised Microsoft 365 calendar to retrieve instructions and store stolen data. Because the traffic appears to be legitimate Microsoft cloud activity, detecting the threat becomes significantly more challenging.
For business owners and leaders, this is another reminder that cybersecurity is no longer just about blocking known bad websites, it’s about monitoring how trusted services are being used within your environment.
Need Advice on Microsoft 365 Security?
Get free insights into the health of your IT estate, with no pushy sales, and no obligation to sign up.
How the HOLLOWGRAPH Malware Works
According to researchers, HOLLOWGRAPH uses compromised Microsoft 365 calendars as a covert communication channel. The malware reads encrypted instructions stored in calendar appointments and uploads stolen information into new calendar events for attackers to collect later.
Interestingly, the malicious calendar appointments were reportedly set for May 13, 2050, placing them far into the future where they are unlikely to draw attention from users or administrators.
The campaign does not exploit a vulnerability in Microsoft 365 itself. Instead, it abuses legitimate functionality in ways most organizations would never expect.
Why Traditional Security Tools May Miss It
Many security solutions are designed to identify suspicious traffic leaving the organization and connecting to unknown external systems.
However, in this campaign:
- Communications occur through legitimate Microsoft cloud services.
- Activity appears similar to normal business application traffic.
- Commands are transmitted using trusted APIs (the digital channels Microsoft 365 apps normally use to talk to each other).
- Data remains within services many businesses already allow and trust.
This makes it harder for conventional perimeter-based defenses (security tools that watch for threats coming from outside the organization) to distinguish between normal and malicious activity.
The Growing Trend of “Living Off Trusted Services”
Cybercriminals are increasingly shifting away from obviously malicious infrastructure and instead hiding within platforms organizations depend on daily.
This approach offers several advantages:
- Reduced likelihood of detection
- Lower infrastructure costs for attackers
- Easier blending into normal user activity
- Greater ability to bypass traditional security controls
The HOLLOWGRAPH campaign highlights how cloud platforms can become part of an attacker’s toolkit when compromised accounts or credentials are available.
Protecting Your Organization
While this specific campaign appears highly targeted, the defensive lessons apply to organizations of all sizes. Researchers identified only a small number of affected systems, indicating a focused espionage operation rather than mass-scale malware distribution.
To reduce risk, businesses should:
- Enable Multi-Factor Authentication (MFA) on all accounts, requiring a second proof of identity, like a phone code, in addition to a password.
- Monitor for unusual calendar activity and unexpected automation.
- Review sign-in logs for anomalous authentication attempts.
- Implement Conditional Access policies where appropriate, rules that restrict sign-ins based on factors like device, location, or risk level.
- Adopt Endpoint Detection and Response (EDR) solutions, software that watches devices for suspicious behavior in real time.
- Regularly audit privileged accounts and cloud permissions.
- Train employees to recognize phishing attempts that may lead to account compromise.
What This Means for Your Business
The most important takeaway is that trusted platforms are not automatically safe from abuse.
Microsoft 365 remains a highly secure platform, but attackers continue to find creative ways to misuse legitimate features after gaining access to compromised accounts. The challenge for businesses is no longer simply blocking malware, it is gaining visibility into how cloud services are being used and identifying abnormal behavior before it becomes a serious incident.
Organizations that combine strong identity security, proactive monitoring, and regular security reviews are in a far better position to detect and respond to these evolving threats.
Need Advice on Microsoft 365 Security?
If you’d like to better understand your organization’s Microsoft 365 security posture, our support team can help review your environment, identify potential risks, and recommend practical improvements that align with your business needs.
Want help with your IT?
Get free insights into the health of your IT estate, with no pushy sales, and no obligation to sign up.

