HollowGraph: Iran-Linked Espionage Hides C2 in Microsoft 365 Calendar Events Dated 2050

Group-IB has uncovered HollowGraph, a technique that hides command and control traffic inside legitimate Microsoft 365 calendar events, some dated to the year 2050, attributed with high confidence to an Iran-linked espionage cluster.

Omar Al-Hakeem
Senior Cyber Threat Analyst | MENA Region3 min read
Laptop displaying an abstract calendar interface representing a covert command and control technique

Laptop displaying an abstract calendar interface representing a covert command and control technique

Researchers at Group-IB have uncovered HollowGraph, a novel espionage technique that hides command and control communication and stolen data inside ordinary Microsoft 365 calendar events, some deliberately dated to the year 2050, allowing the activity to blend into legitimate enterprise traffic almost entirely.

Attribution and origin

Group-IB attributes HollowGraph with high confidence to Cavern, a framework Check Point previously linked to an Iranian intelligence-aligned cluster with overlapping tradecraft to MuddyWater and Lyceum, both threat actors with a long history of targeting government, telecommunications, and enterprise organisations across the Middle East.

Why calendar events make an unusually effective hiding place

The technique works by tasking compromised endpoints and exfiltrating stolen data through legitimate Microsoft Graph API calls, the same programmatic interface used by ordinary business applications to read and write calendar entries. Because every request rides through Microsoft's own authenticated API infrastructure using standard calendar functionality, the traffic looks identical to routine M365 activity to most network monitoring tools. Calendar events dated to 2050 function as a kind of dead drop, sitting far enough in the future that they are unlikely to appear in a user's normal view, while still being fully readable and writable by anyone with API access to the account.

No patch applies here

Unlike most of the vulnerability disclosures covered this week, HollowGraph does not stem from a software flaw that Microsoft can simply patch. It abuses legitimate, intended functionality within Microsoft 365, which places the burden of detection on behavioural monitoring and anomaly detection rather than a vendor fix. That distinction matters operationally: patch management workflows do nothing against this technique, since there is nothing broken to patch.

Why this matters for identity and cloud security teams

This is fundamentally an identity and access problem rather than a traditional malware problem. Any compromised account or service principal with calendar API permissions becomes a viable channel, meaning the relevant defensive question is not what software needs updating, but which identities and applications should legitimately have that level of Graph API access in the first place, and whether that access is being monitored for unusual patterns such as events created with implausible future dates or unusual creation frequency. This connects to the broader theme of trust exploitation we detailed in our coverage of GoldenEyeDog's hijacking of DigiCert code-signing certificates, where attackers again succeeded not by breaking a system technically, but by abusing a mechanism that was functioning exactly as designed. It also echoes the exposure we mapped in our research on privileged access being the GCC's biggest identity risk. Organisations relying heavily on Microsoft 365 across government, telecommunications, and enterprise environments, sectors with a documented history of MuddyWater and Lyceum targeting, should treat this as a prompt to review Graph API permission scopes and calendar-based anomaly detection specifically, rather than waiting on a patch that will not be coming.

Omar Al-Hakeem

Senior Cyber Threat Analyst | MENA Region

Omar Al-Hakeem is a cybersecurity researcher specializing in threat intelligence, ransomware trends, and nation-state activity across the Middle East and North Africa. With over 12 years of experience in SOC operations and incident response, he provides deep technical breakdowns of emerging attacks and regional cyber risks. At MENA Cyber Wire, Omar focuses on real-world threat analysis and actionable defense strategies for enterprises and startups.

Intelligence Focus Areas

Threat IntelligenceNation State Threat ActorsCloud and Identity Security