🔐
Security 📅 2026-07-20 · 03:22 PM IST ⏱ 3 min read

Hackers Hide Instructions Inside Fake Calendar Events to Control Stolen Data

Researchers discover malware using Microsoft 365 calendars as hidden messaging system for cyberattacks.

A Hidden Communication Channel Inside Your Calendar

Security researchers have uncovered a sophisticated attack where cybercriminals planted malicious software that secretly uses Microsoft 365 calendar features to receive orders and transmit stolen information. The malware, identified by Group-IB researchers and dubbed HollowGraph, takes advantage of a system millions of people use every day—turning ordinary calendar events into a covert intelligence network operating right under security teams' noses.

The attack works like an invisible dead drop. Instead of sending commands through traditional internet channels that security tools monitor, attackers create calendar events scheduled for the year 2050—dates far enough in the future that they blend into normal calendar clutter. These fake events contain hidden instructions for the malware, while the same calendar events are used to attach and transmit confidential files back to the attackers. It's a clever disguise: calendar activity looks completely ordinary to anyone watching network traffic.

What This Means

This discovery reveals how attackers continue evolving their methods to avoid detection. Traditional security tools focus on blocking suspicious internet connections and monitoring email traffic. But using a legitimate cloud service like Microsoft 365 as a command center creates a blind spot—the traffic appears to be normal business activity rather than a cyberattack.

Think of it like a spy delivering messages hidden inside postcards sent through the regular mail. Security guards inspect packages crossing the border, but postcards get waved through because they seem harmless. Similarly, calendar synchronization between devices and Microsoft's servers looks entirely normal to security systems.

The 2050 date selection is deliberately strategic. Calendar entries years in the future won't trigger time-based alerts or stand out in routine reviews of recent activity. An attacker could plant multiple sets of instructions over time, essentially scheduling future attacks months or years ahead.

Why You Should Care

If your organization uses Microsoft 365, this matters directly to you. This malware demonstrates that attackers no longer need to maintain suspicious external connections. They can hide within the tools your company already trusts and pays for.

Companies managing large numbers of Microsoft 365 accounts face particular risk, since the volume of calendar activity makes suspicious events harder to spot manually.

What You Can Do

Start with fundamental security practices:

Organizations should also consider deploying advanced threat detection tools that understand cloud-based communication patterns, not just traditional network traffic.

This attack pattern shows that your security strategy must evolve beyond blocking suspicious websites and email—protecting your cloud services requires the same vigilance.

📎 This is original ITVedas reporting. This story was inspired by coverage from source. Visit the source for their original reporting.

Want to understand the technology behind this story? ITVedas has beginner-friendly guides on every IT topic.

Explore IT Chapters →