China-linked hackers exploit Google Calendar in cyberattacks on governments
ID: 380ddc52-822c-5afb-ba24-f2cbd740edf4
STIX ID: report--380ddc52-822c-5afb-ba24-f2cbd740edf4
Feed Name: The Record from Recorded Future News
Threat Score
Google analysts attributed a late-October espionage campaign to China-linked APT41 in which spearphishing led victims to a malicious ZIP hosted on a hijacked government site; the archive deployed a stealthy in-memory malware family dubbed ToughProgress that used Google Calendar as a covert command-and-control and data exfiltration channel by embedding encrypted data and commands into calendar events.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
