In the current cybersecurity landscape, attackers are constantly seeking new ways to bypass traditional defenses. The recent HOLLOWGRAPH campaign represents a qualitative leap in using legitimate services to hide malicious activities. Group-IB researchers have discovered a malware component that uses Microsoft 365 calendars as a command-and-control channel, storing instructions and stolen files in appointments dated May 13, 2050. This approach, leveraging the Microsoft Graph API, turns an everyday service into a perfect hiding place for espionage.
HOLLOWGRAPH does not exploit vulnerabilities in Microsoft 365 but rather blends into normal traffic flow. Instead of connecting to attacker-controlled servers, the malware retrieves encrypted tasks from calendar events and drops stolen data into new appointments. All of this is done through legitimate Graph API requests, which are indistinguishable from traffic generated by authorized corporate applications. The component is relatively lightweight: its main function is to read instructions from one event, write files into another, and periodically renew Entra ID credentials via DNS tunneling. This allows the communication with the compromised calendar to remain operational without raising suspicion.
The campaign appears to be highly targeted. Group-IB identified only twelve infected systems, of which only three communicated with the compromised mailbox during the observation period. The mailbox used for C2 belonged to an Israeli organization, and malware samples were uploaded from Israel. Everything points to a focused espionage operation, not a mass attack. Additionally, researchers linked HOLLOWGRAPH to the Cavern framework with high confidence and found similarities with the Iranian-linked Lyceum group, though without definitive attribution.
From a technical perspective, this attack underscores the importance of monitoring not only outbound traffic to unknown IPs but also unusual usage of cloud services. Traditional perimeter defenses, such as firewalls or intrusion detection systems, do not detect these activities because the malware uses legitimate APIs and valid authentication. For businesses, this implies a paradigm shift: security must focus on the internal behavior of applications and access to sensitive data, not just on blocking external connections.
In this context, having advanced cybersecurity solutions becomes essential. At Q2BSTUDIO, as a software and technology development company, we help organizations implement defense-in-depth strategies that include API monitoring, behavior analysis, and anomaly detection in cloud environments. Our custom custom software services allow integrating personalized controls tailored to each client's infrastructure, whether on AWS or Azure.
The HOLLOWGRAPH campaign also highlights the need for robust identity management. By renewing credentials via DNS tunneling, the malware demonstrates that even authentication systems can be bypassed if not properly monitored. Artificial intelligence solutions applied to cybersecurity, such as the AI agents we develop at Q2BSTUDIO, can analyze traffic patterns and detect suspicious behaviors, such as creating calendar events with atypical future dates or using access tokens for unusual operations. AI enables automated incident response and reduces detection time, a critical factor in stealthy campaigns like this one.
Another relevant aspect is the integration of business intelligence. BI/Power BI tools can help visualize activity logs and correlate events across different cloud services, facilitating the identification of anomalous patterns. For example, a dashboard showing the frequency of Graph API access from various applications could alert about unusual calendar usage. At Q2BSTUDIO, we combine these BI capabilities with custom software development to provide tailored monitoring solutions.
The cloud, both AWS and Azure, is the ecosystem where most of these attacks unfold. HOLLOWGRAPH shows that attackers are comfortable exploiting managed services because they trust they will go unnoticed. That is why at Q2BSTUDIO we offer cloud AWS/Azure services that include security audits, conditional access policy configuration, and deployment of zero trust architectures. The key is to design environments where every request is verified, regardless of its origin, and where the use of APIs like Microsoft Graph is restricted according to the principle of least privilege.
Furthermore, process automation plays a fundamental role in threat response. At Q2BSTUDIO we develop AI agents that can autonomously execute corrective actions, such as revoking suspicious tokens or blocking the creation of events in shared calendars. These agents integrate with orchestration platforms and enable immediate reaction without human intervention, reducing the impact of campaigns like HOLLOWGRAPH.
In conclusion, the HOLLOWGRAPH campaign is a reminder that cloud services, no matter how legitimate, can become attack vectors if not properly monitored. Companies must adopt a proactive approach that combines advanced cybersecurity, artificial intelligence, data analytics, and custom software. At Q2BSTUDIO, we are prepared to help organizations protect against these threats, offering solutions ranging from cloud consulting to the development of customized AI agents. Security is no longer a product but a continuous process that requires constant adaptation. And in that process, Q2BSTUDIO's technology is a strategic ally.




