APT41 malware abuses Google Calendar for stealthy C2 communication
'ToughProgress' is a new piece of malware used by the Chinese hacker collective APT41 that utilizes Google Calendar for command-and-control (C2) operations, concealing harmful activities behind a reliable cloud service.
Google's Threat Intelligence Group uncovered the campaign, located and decommissioned attacker-controlled Google Calendar and Workspace infrastructure, and implemented focused safeguards to stop future abuse.
It's not a new method to use Google Calendar as a C2 mechanism; Veracode recently revealed a malicious package in the Node Package Manager (NPM) index that used a similar strategy.
Additionally, APT41 has a history of misusing Google services, such as in a Voldemort malware operation in April 2023 when it used Google Sheets read more about APT41 malware abuse...

