The HollowGraph malware abuses Microsoft Graph API and a compromised 365 account’s calendar for C&C communication.

HollowGraph uses Microsoft 365 calendar events dated to 2050 to receive commands and exfiltrate encrypted files through legitimate Graph API traffic.

Malware hides commands in appointments set for 2050 and uses Redmond's own cloud to phone home