logo

APT41 malware abuses Google Calendar for stealthy C2 communication

ID: 4364baca-901c-5ecf-a066-23f9666c250d

STIX ID: report--4364baca-901c-5ecf-a066-23f9666c250d

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2025-05-28

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

APT41 deployed a sophisticated multi-stage Windows malware (PlusDrop → PlusInject → ToughProgress) delivered via a malicious LNK and image-disguised payloads; the final stage performs in-memory process hollowing and uses Google Calendar event descriptions as an encrypted C2 channel to receive commands and return results. Google discovered and terminated attacker-controlled Workspace accounts and calendar events, updated Safe Browsing blocklists, and shared samples and traffic logs with affected parties to help detect infections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.