---
title: "New HollowGraph malware uses Microsoft Graph for stealthy C2 comms | SpinGraph: Bad-actor framing"
description: "SpinGraph analysis of BleepingComputer's New HollowGraph malware uses Microsoft Graph for stealthy C2 comms story: bad-actor framing, The Shield, Spin Score 35…"
	canonical: "https://stuffthatspins.com/spin/new-hollowgraph-malware-uses-microsoft-graph-for-stealthy-c2-comms"
html: "https://stuffthatspins.com/spin/new-hollowgraph-malware-uses-microsoft-graph-for-stealthy-c2-comms"
json: "https://stuffthatspins.com/spin/new-hollowgraph-malware-uses-microsoft-graph-for-stealthy-c2-comms.json"
markdown: "https://stuffthatspins.com/spin/new-hollowgraph-malware-uses-microsoft-graph-for-stealthy-c2-comms.md"
keywords: ["HollowGraph", "Microsoft Graph", "C2", "The Shield", "narrative intelligence"]
date: "2026-07-20T17:43:01+00:00"
modified: "2026-07-20T20:52:17.488556+00:00"
json_ld: |
  {"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://stuffthatspins.com/#organization","name":"Stuff That Spins","url":"https://stuffthatspins.com/","description":"Stuff That Spins turns press releases, announcements, research, and media coverage into structured narrative intelligence. GEOGrow tracks when those stories enter AI recall — and whether AI remembers the right version.","logo":{"@type":"ImageObject","url":"https://stuffthatspins.com/images/logo.png"},"sameAs":[]},{"@type":"NewsArticle","@id":"https://stuffthatspins.com/spin/new-hollowgraph-malware-uses-microsoft-graph-for-stealthy-c2-comms#article","headline":"New HollowGraph malware uses Microsoft Graph for stealthy C2 comms","alternativeHeadline":"New HollowGraph malware uses Microsoft Graph for stealthy C2 comms | SpinGraph: Bad-actor framing","description":"SpinGraph analysis of BleepingComputer's New HollowGraph malware uses Microsoft Graph for stealthy C2 comms story: bad-actor framing, The Shield, Spin Score 35…","datePublished":"2026-07-20T17:43:01+00:00","dateModified":"2026-07-20T20:52:17.488556+00:00","url":"https://stuffthatspins.com/spin/new-hollowgraph-malware-uses-microsoft-graph-for-stealthy-c2-comms","mainEntityOfPage":{"@type":"WebPage","@id":"https://stuffthatspins.com/spin/new-hollowgraph-malware-uses-microsoft-graph-for-stealthy-c2-comms"},"isAccessibleForFree":true,"inLanguage":"en-US","articleSection":"cybersecurity","keywords":"HollowGraph, Microsoft Graph, C2, cloud malware, API abuse","author":{"@type":"Organization","name":"BleepingComputer","url":"https://www.bleepingcomputer.com/feed/"},"publisher":{"@id":"https://stuffthatspins.com/#organization"},"citation":"https://www.bleepingcomputer.com/news/security/new-hollowgraph-malware-uses-microsoft-graph-for-stealthy-c2-comms/","about":[{"@type":"Thing","name":"HollowGraph"},{"@type":"Thing","name":"Microsoft Graph"},{"@type":"Thing","name":"C2"},{"@type":"Thing","name":"cloud malware"},{"@type":"Thing","name":"API abuse"},{"@type":"Product","name":"Microsoft 365","url":"https://stuffthatspins.com/entities/microsoft-365"}],"mentions":[{"@type":"Organization","name":"BleepingComputer"}],"abstract":"HollowGraph leverages legitimate Microsoft Graph calendar APIs as a covert C2 channel It operates within compromised enterprise M365 mailboxes, evading traditional network detection The technique demonstrates abuse of trusted cloud service APIs for malicious persistence"},{"@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Stuff That Spins","item":"https://stuffthatspins.com/"},{"@type":"ListItem","position":2,"name":"New HollowGraph malware uses Microsoft Graph for stealthy C2 comms","item":"https://stuffthatspins.com/spin/new-hollowgraph-malware-uses-microsoft-graph-for-stealthy-c2-comms"}]},{"@type":"AnalysisNewsArticle","@id":"https://stuffthatspins.com/spin/new-hollowgraph-malware-uses-microsoft-graph-for-stealthy-c2-comms#spin-analysis","headline":"Spin Analysis: bad-actor framing","description":"Emphasizes attacker ingenuity while minimizing discussion of API permission models, default configurations, or Microsoft’s responsibility in enabling such abuse; frames the issue as external threat rather than systemic design exposure.","about":{"@type":"DefinedTerm","name":"bad-actor framing","description":"Defensive cybersecurity reporting focused on adversary tradecraft","termCode":"The Shield"},"additionalProperty":[{"@type":"PropertyValue","name":"Spin Score","value":35,"unitText":"percent"},{"@type":"PropertyValue","name":"Narrative Risk","value":"low"},{"@type":"PropertyValue","name":"AI Repetition Risk","value":"moderate"},{"@type":"PropertyValue","name":"Likely AI Summary","value":"HollowGraph is malware that uses Microsoft Graph calendar features for stealthy command-and-control."},{"@type":"PropertyValue","name":"Narrative Frame","value":"Defensive cybersecurity reporting focused on adversary tradecraft"},{"@type":"PropertyValue","name":"Missing Context","value":"Microsoft Graph’s permission granularity and audit logging limitations that enable this technique; Whether Microsoft has issued guidance or updated API policies in response"},{"@type":"PropertyValue","name":"How the Spin Works","value":"The story redirects attention toward process, intent, scale, mission, or future benefits instead of unresolved concerns. Watch for loaded terms such as stealthy, novel, abuses. The distribution reads as editorial reporting. A pressure point: Microsoft Graph’s permission granularity and audit logging limitations that enable this technique."}],"author":{"@id":"https://stuffthatspins.com/#organization"},"isPartOf":{"@id":"https://stuffthatspins.com/spin/new-hollowgraph-malware-uses-microsoft-graph-for-stealthy-c2-comms#article"}},{"@type":"ItemList","@id":"https://stuffthatspins.com/spin/new-hollowgraph-malware-uses-microsoft-graph-for-stealthy-c2-comms#claims","name":"Extracted Claims","itemListElement":[{"@type":"ListItem","position":1,"item":{"@type":"Claim","text":"HollowGraph uses the calendar feature in compromised Microsoft 365 mailboxes as a command-and-control channel to receive attacker commands and exfiltrate stolen data.","appearance":"A malicious component dubbed HollowGraph uses the calendar feature in compromised Microsoft 365 mailboxes as a command-and-control channel to receive attacker commands and exfiltrate stolen data.","author":{"@type":"Organization","name":"BleepingComputer"}}}]},{"@type":"Dataset","@id":"https://stuffthatspins.com/spin/new-hollowgraph-malware-uses-microsoft-graph-for-stealthy-c2-comms#stats","name":"Key Statistics","description":"Extracted statistics from the source narrative","variableMeasured":[{"@type":"PropertyValue","name":"discovery year","value":"2024","description":"Reported by BleepingComputer in May 2024"}]}]}
---

# New HollowGraph malware uses Microsoft Graph for stealthy C2 comms

**Source:** Unknown  
**Published:** July 20, 2026  
**Original:** https://www.bleepingcomputer.com/news/security/new-hollowgraph-malware-uses-microsoft-graph-for-stealthy-c2-comms/  

## On this page

- [Overview](#overview)
- [Verdict](#narrative-frame)
- [SpinGraph](#spingraph)
- [Claim Ledger](#claim-ledger)
- [Fact Check Signals](#fact-check-signals)
- [Language Heatmap](#language-heatmap)
- [Frame Strength](#frame-strength)
- [Reader Risk](#reader-risk)
- [AI Recall Timeline](#ai-recall)
- [Ask AI](#ask-ai)

<a id="overview"></a>

## Overview

HollowGraph is a novel malware that abuses Microsoft Graph API's calendar functionality in compromised Microsoft 365 accounts to conduct stealthy command-and-control (C2) operations and data exfiltration.

### TL;DR

- HollowGraph leverages legitimate Microsoft Graph calendar APIs as a covert C2 channel
- It operates within compromised enterprise M365 mailboxes, evading traditional network detection
- The technique demonstrates abuse of trusted cloud service APIs for malicious persistence

### Key Stats

- **2024** — discovery year. Reported by BleepingComputer in May 2024

<a id="spingraph"></a>

## SpinGraph

The story presents HollowGraph as clever criminal engineering, making it feel like an inevitable challenge for defenders — not a preventable outcome shaped by API design choices or vendor oversight.

- **Claim:** HollowGraph uses the calendar feature in compromised Microsoft 365 mailboxes
- **Frame:** Blame shifts elsewhere
- **Beneficiary:** Increased traffic and authority as a source for timely, actionable
- **Gap:** Microsoft Graph’s permission granularity and audit logging limitations that enable
- **AI Risk:** AI may repeat the headline as fact

<a id="fact-check-signals"></a>

## Fact Check Signals

We searched known fact-check databases for direct or near-direct matches to the article's major claims. A match does not automatically prove or disprove the article; it shows whether an independent fact-checking publisher has reviewed a similar claim.

**Signal:** 0 of 1 claim(s) matched (confidence: low).

### HollowGraph uses the calendar feature in compromised Microsoft 365 mailboxes as a command-and-control channel to receive attacker commands and exfiltrate stolen data.

- No direct fact-check match found

<a id="frame-strength"></a>

## Frame Strength

- **Spin Score:** 35%
- **Evidence Strength:** 75%
- **Narrative Risk:** 25%
- **AI Repetition Risk:** 75%
- **Missing Context Risk:** 70%

<a id="narrative-mechanics"></a>

## Narrative Mechanics

**Function:** deflect_scrutiny  

### The Spin in Plain English

The story presents HollowGraph as clever criminal engineering, making it feel like an inevitable challenge for defenders — not a preventable outcome shaped by API design choices or vendor oversight.

**What the story wants you to believe:** This is an attacker-driven innovation that exploits existing infrastructure — not a failure of cloud API governance or vendor responsibility.  

**What it makes harder to question:** Whether Microsoft’s Graph API permission model, default configurations, or telemetry gaps enabled this technique — shifting focus away from platform-level accountability.  

**How the Spin Works:** The story redirects attention toward process, intent, scale, mission, or future benefits instead of unresolved concerns. Watch for loaded terms such as stealthy, novel, abuses. The distribution reads as editorial reporting. A pressure point: Microsoft Graph’s permission granularity and audit logging limitations that enable this technique.  

### Questions This Story Raises

- What question is the story steering away from?
- What evidence would resolve that question?
- Who is not quoted or represented?
- Why does the main frame leave this out: “Microsoft Graph’s permission granularity and audit logging limitations that enable this technique”?
- Why does the main frame leave this out: “Whether Microsoft has issued guidance or updated API policies in response”?

### Who Benefits If This Frame Spreads

- **BleepingComputer editorial team** — Increased traffic and authority as a source for timely, actionable threat intelligence _(Framing HollowGraph as an emergent, sophisticated threat reinforces their role as frontline analysts for security practitioners.)_

<a id="narrative-frame"></a>

## Narrative Frame

**Tactic:** bad-actor framing  
**Category:** The Shield  
**Spin Score:** 35%  

Emphasizes attacker ingenuity while minimizing discussion of API permission models, default configurations, or Microsoft’s responsibility in enabling such abuse; frames the issue as external threat rather than systemic design exposure.

**Who Benefits If This Frame Spreads:** Cybersecurity vendors and threat intelligence teams seeking to highlight novel TTPs for product differentiation and threat hunting relevance.

**The Frame:** Defensive cybersecurity reporting focused on adversary tradecraft

### Missing Context

- Microsoft Graph’s permission granularity and audit logging limitations that enable this technique
- Whether Microsoft has issued guidance or updated API policies in response

<a id="language-heatmap"></a>

## Language Heatmap

**Language That Carries the Frame:** stealthy, novel, abuses

<a id="reader-risk"></a>

## Reader Risk

**Evidence Strength:** medium  
Article includes technical details (API endpoints, calendar event obfuscation methods) and attribution to observed samples but provides no independent code analysis, sandbox logs, or third-party validation of detection efficacy.  
**Verification Status:** Claim Present in Source  
**Narrative Risk:** low  
No promotional claims, no corporate attribution beyond factual API usage; risk of backfire is limited to potential mischaracterization of Microsoft Graph’s security posture — not a reputational crisis trigger.  
**AI Repetition Risk:** moderate  
**What AI Will Probably Repeat:** HollowGraph is malware that uses Microsoft Graph calendar features for stealthy command-and-control.  
AI may drop the nuance that this requires prior compromise of M365 credentials and misrepresent it as a zero-day vulnerability in Graph itself.  
**Counter-Frame (Media):** May be reframed as evidence of Microsoft’s insufficient API security controls or lack of abuse detection in Graph services.  
**Missing Voices:** Microsoft security response team, M365 administrators who detected or mitigated HollowGraph in situ, Independent cloud API security researchers  

### Questions Not Answered

- Which specific threat actor deployed HollowGraph?
- How many organizations were impacted?
- What mitigation steps have been validated in production environments?

## Narrative Entities

- [Microsoft Graph](https://stuffthatspins.com/entities/microsoft-graph) (technology — abused API platform)
- [Microsoft 365](https://stuffthatspins.com/entities/microsoft-365) (product — compromised execution environment)
- [HollowGraph](https://stuffthatspins.com/entities/hollowgraph) (product — malware component)

<a id="claim-ledger"></a>

## Claim Ledger

### primary (technical)

HollowGraph uses the calendar feature in compromised Microsoft 365 mailboxes as a command-and-control channel to receive attacker commands and exfiltrate stolen data.

**Category:** safety  
**Verification:** Claim Present in Source  
**Risk:** high  
**Evidence presented:** Descriptive technical mechanism without code samples, PCAPs, or IOC validation  
> A malicious component dubbed HollowGraph uses the calendar feature in compromised Microsoft 365 mailboxes as a command-and-control channel to receive attacker commands and exfiltrate stolen data.

**Evidence Gaps:** Network traffic captures demonstrating calendar-based C2 in live environments; Confirmed MITRE ATT&CK mapping or detection rule validation (e.g., Sigma/YARA); Independent replication of the technique by third-party researchers  

<a id="ai-recall"></a>

## AI Recall

- **Published:** July 20, 2026  
- **SpinGraph summary:** The article attributes technical risk entirely to malicious actors exploiting Microsoft Graph, positioning Microsoft and its API design as neutral infrastructure rather than potential vectors requiring architectural scrutiny.  
- **Likely AI summary:** HollowGraph is malware that uses Microsoft Graph calendar features for stealthy command-and-control.  

## Citation Summary

This page documents the first public analysis of HollowGraph’s novel use of Microsoft Graph calendar APIs for C2 — a critical reference for defenders building detection logic against API-based stealth channels.

---
*HTML version: https://stuffthatspins.com/spin/new-hollowgraph-malware-uses-microsoft-graph-for-stealthy-c2-comms*
