logo

Mark Your Calendar: APT41 Innovative Tactics

ID: 376faa3b-4514-5848-89e1-ed9eaa4a9d07

STIX ID: report--376faa3b-4514-5848-89e1-ed9eaa4a9d07

Feed Name: Threat Intelligence

Threat Score
85/100

Date Published: 2025-05-28

Date Updated: 2026-04-27

Author: Google Threat Intelligence Group

...
...

GTIG describes APT41’s ongoing malware campaigns that abused Google Workspace apps and free web-hosting platforms (Cloudflare Workers, InfinityFree, TryCloudflare) and URL shorteners to distribute TOUGHPROGRESS, VOLDEMORT, DUSTTRAP and other payloads; Google disrupted attacker-controlled Calendars and Workspace projects, added domains/URLs and file detections to Safe Browsing, and shared IOCs and traffic samples with affected organizations and partners.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.