Tag: APT41 malware

APT41 malware abuses Google Calendar for stealthy C2 communication
News

APT41 malware abuses Google Calendar for stealthy C2 communication

'ToughProgress' is a new piece of malware used by the Chinese hacker collective APT41 that utilizes Google Calendar for command-and-control (C2) operations, concealing harmful activities behind a reliable cloud service. Google's Threat Intelligence Group uncovered the campaign, located and decommissioned attacker-controlled Google Calendar and Workspace infrastructure, and implemented focused safeguards to stop future abuse. It's not a new method to use Google Calendar as a C2 mechanism; Veracode recently revealed a malicious package in the Node Package Manager (NPM) index that used a similar strategy. Additionally, APT41 has a history of misusing Google services, such as in a Voldemort malware operation in April 2023 when it used Google Sheets read more about APT41 malware abuse...