Key Findings HollowGraph malware uses hijacked Microsoft 365 calendar events dated 2050 as a command-and-control channel, disguising malicious traffic as legitimate Microsoft Graph API activity The .NET implant supports only two commands (get and send) and never connects to attacker-owned servers, instead treating a compromised mailbox calendar as a two-way dead drop Tasking and exfiltrated files are encrypted with hybrid RSA-OAEP and AES-256-GCM encryption, with separate key