Watch out - that Microsoft Calendar invite dated 2050 could be hiding stolen files and worse

https://cdn.mos.cms.futurecdn.net/NK6WMQwJZAmbq9SfRREf2f-2560-80.jpg
  • Group‑IB discovers HollowGraph malware targeting Israeli entities, exfiltrating files via Microsoft Graph API
  • Operators hide instructions in future calendar entries, then attach encrypted stolen data to events
  • At least 12 systems were compromised; overlaps with Lyceum noted but attribution remains low‑confidence

Cybercriminals have found a way to communicate with the malware installed on victim devices through compromised Microsoft Calendar apps, experts have warned.

Security researchers at Group-IB have detailed a newly discovered piece of malware called HollowGraph designed to exfiltrate sensitive files from compromised devices.

What makes the malware stand out is the way it communicates with its operators. The best way to spot hidden malware is to monitor the traffic flowing in and out of a device, which is why cybercriminals try their best to hide this traffic, or blend it with another, legitimate one. In that respect, HollowGraph is unique because it abuses Microsoft Graph API and a...

Copyright of this story solely belongs to techradar.com. To see the full text click HERE

Read more