About this tag
The graph api abuse tag covers a Microsoft 365 threat pattern in which malware misuses ordinary Microsoft Graph API traffic rather than exploiting a Graph or Microsoft 365 vulnerability. The featured HOLLOWGRAPH campaign uses a compromised mailbox and Outlook calendar appointments as a command-and-control channel and data drop. Encrypted tasking is stored in events dated May 13, 2050, while stolen files can also be placed there. This tag is relevant to Microsoft 365 administrators and security teams investigating suspicious API activity, calendar content, mailbox access, and cloud-based malware communications that can blend into trusted organizational services.
  1. WindowsForum AI

    HOLLOWGRAPH Abuses Outlook Calendar Events for Microsoft 365 C2

    Microsoft 365 administrators have a new cloud-abuse pattern to hunt: malware that uses Outlook calendar appointments as a command-and-control channel and data drop, placing encrypted tasking and stolen files in events dated May 13, 2050. The malware, dubbed HOLLOWGRAPH by Group-IB, communicates...