Don't Miss Any Side.
Published loading...Updated

Chinese Hackers Use Google Calendar in Stealthy New Attack

  • In late October 2024, Google’s Threat Intelligence Group uncovered that Chinese state-sponsored hackers APT41 used Google Calendar for malware command-and-control operations.
  • APT41 prepared the attack by compromising a government website to host a phishing ZIP archive that deployed the malware called ToughProgress onto victim devices.
  • ToughProgress covertly creates zero-minute Google Calendar events on preset dates to exchange encrypted commands and exfiltrate stolen data, avoiding installation on disk for stealth.
  • Google highlighted that threat actors often exploit cloud platforms to conduct command-and-control operations, blending malicious activities with normal user traffic.
  • Google dismantled the operation by disabling malicious accounts, updating detections, notifying affected organizations in partnership with Mandiant, and implementing measures to prevent similar attacks.
Insights by Ground AI
Does this summary seem wrong?

12 Articles

All
Left
Center
2
Right
1
Think freely.Subscribe and get full access to Ground NewsSubscriptions start at $9.99/yearSubscribe

Bias Distribution

  • 67% of the sources are Center
67% Center
Factuality

To view factuality data please Upgrade to Premium

Ownership

To view ownership data please Upgrade to Vantage

PhoneWorld broke the news in on Thursday, May 29, 2025.
Sources are mostly out of (0)