APT41 Uses Google Calendar Events for C2
ID: f3413b2a-6ecb-58a8-a2de-2cb8c2bf88f9
STIX ID: report--f3413b2a-6ecb-58a8-a2de-2cb8c2bf88f9
Feed Name: Dark Reading
Date Published: 2025-05-29
Date Updated: 2026-04-21
Author: Alexander Culafi, Senior News Writer, Dark Reading
APT41 conducted a spear-phishing campaign against government targets that deployed a three-stage malware chain (PLUSDROP → PLUSINJECT → TOUGHPROGRESS). TOUGHPROGRESS abused Google Calendar events as an encrypted read/write C2 channel to issue commands and exfiltrate results; Google disrupted attacker-controlled calendars and Workspace projects and published IoCs and detection guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
