New Malware Hides in Microsoft Calendar Invites to Steal Data from Israeli Targets
AI-generated from multiple sources. Verify before acting on this reporting.
JERUSALEM — Additional corroborating reports have emerged regarding the HOLLOWGRAPH malware campaign targeting Israeli entities. These new findings further confirm the scope of the intrusion, validating earlier assessments that the malicious code utilizes Microsoft 365 calendar invitations to establish covert command-and-control channels. The expanded intelligence indicates a broader deployment pattern than initially observed on July 20, suggesting the threat actors have successfully infiltrated multiple organizational networks across the region. Security teams are now advised to scrutinize all recent calendar invites from external sources for signs of this specific exfiltration technique. While the core mechanics of the malware remain consistent with previous descriptions, the volume of confirmed incidents points to an active and expanding operation rather than isolated testing phases.
JERUSALEM — Cybersecurity researchers have identified a new malware strain capable of hiding within legitimate Microsoft 365 calendar invitations, using the cloud service as a covert channel for command-and-control communications and data exfiltration. The discovery marks a significant evolution in espionage tactics that leverage trusted enterprise infrastructure to bypass traditional security defenses.
The malicious software, dubbed HOLLOWGRAPH by Group-IB researchers, was uncovered on July 20, 2026, during an investigation into compromised mailboxes located primarily within Israel. Unlike conventional malware that relies on external servers or suspicious file downloads, HOLLOWGRAPH embeds its instructions and stolen data directly inside the metadata of calendar events sent to victims' accounts.
By utilizing Microsoft's own global cloud infrastructure, the attackers establish a persistent communication channel that appears indistinguishable from standard business scheduling activity. The technique allows threat actors to issue commands to infected systems and extract sensitive information without triggering alerts typically associated with outbound connections to known malicious domains or unusual network traffic patterns.
The operation is attributed by analysts to an Iranian-nexus actor, potentially linked to the Cavern framework previously observed in campaigns also designated as Lyceum or OilRig. These groups have a history of targeting government entities and critical infrastructure for intelligence gathering purposes. The use of Microsoft 365 features suggests a sophisticated understanding of cloud environments and a deliberate strategy to exploit user trust in established productivity tools.
Victims of the campaign received calendar invites that appeared normal on the surface but contained hidden code designed to execute upon opening or viewing specific event details. Once activated, the malware began siphoning data from compromised devices while maintaining contact with operators through subsequent scheduled meetings and updates. The scope of the attack extends beyond Israel, as the reliance on Microsoft's global infrastructure implies potential reach across international borders.
Security experts note that this method complicates detection efforts because standard email filters often whitelist calendar invites to ensure business continuity. Traditional signature-based defenses may fail to identify the threat if it does not involve executable files or known malicious URLs. The incident highlights a growing trend among state-sponsored groups to weaponize legitimate software functionality for espionage.
Microsoft has acknowledged reports of suspicious activity involving its cloud services but has not yet released specific details regarding mitigation steps for this particular variant. As organizations review their calendar security settings, questions remain about the full extent of data compromised and whether other Microsoft 365 features are being similarly exploited by advanced persistent threats.