A newly discovered malware component called HollowGraph abuses Microsoft 365 calendar events as a covert command-and-control (C2) channel. It authenticates to the Microsoft Graph API using hardcoded credentials from a compromised M365 account, hiding commands and exfiltrated data in calendar entries dated May 13, 2050. Communication is secured with hybrid RSA and AES-256-GCM encryption, with a secondary DNS tunneling channel used to refresh authentication credentials via IPv6 AAAA record queries. Group-IB researchers link HollowGraph to the Cavern C2 framework and note technical similarities with the Iranian-linked Lyceum threat actor. At least 12 systems have been infected, with targets appearing to be organizations in Israel. Defenders are advised to monitor Microsoft Graph audit logs for unusual calendar activity, restrict OAuth client-credential apps, and watch for DNS tunneling patterns.