Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Nation-State

Chinese Hacking Group APT41 Exploits Google Calendar to Target Governments

China-linked hackers used a compromised government site to target other government entities with the ToughProgress malware that uses an attacker-controlled Google Calendar for C&C.

APT24 BadAudio supply-chain

Chinese state-sponsored threat actor APT41 has targeted government entities with malware that uses Google Calendar for command-and-control (C&C), Google warns.

Also tracked as Barium, Winnti, Wicked Panda and Wicked Spider, APT41 is known for targeting organizations globally, across multiple sectors, including automotive, entertainment, government, logistics, media, shipping, and technology sectors.

In attacks observed in October 2024, the threat actor used a compromised government site to target other government entities with the ToughProgress malware that uses an attacker-controlled Google Calendar for C&C.

APT41 relied on phishing emails containing a link to a ZIP archive hosted on the compromised website, which contained a LNK file posing as a PDF document.

When opened, the LNK file launched a DLL (dubbed PlusDrop) that executed the next stage (PlusInject) designed to inject the final payload (ToughProgress) into the legitimate svchost process, using the process hollowing technique.

Upon execution, ToughProgress would create a zero-minute Calendar event at a hardcoded date writing to the event description data collected from the compromised machine, encrypted. The malware can also read hardcoded Calendar events, to which the operator writes commands.

Advertisement. Scroll to continue reading.

“When an event is retrieved, the event description is decrypted and the command it contains is executed on the compromised host. Results from the command execution are encrypted and written back to another Calendar event,” Google explains.

The internet giant says it developed custom fingerprints it used to find and take down APT41-controlled Calendars, and identified and disrupted the group’s Workspace projects, to disrupt its infrastructure.

Google also added detections to the Google Safe Browsing blocklist, notified the affected organizations, and provided them with a sample of the ToughProgress network traffic logs to help with their detection and remediation efforts.

Additionally, Google warned that since August 2024, APT41 was seen using free web hosting tools for the distribution of malware such as Voldemort, DustTrap, ToughProgress, and others. Hundreds of entities were served links to these hosting sites.

Related: Chinese Hacking Group APT41 Infiltrates Global Shipping and Tech Sectors

Related: Chinese Hacking Group ‘Earth Lamia’ Targets Multiple Industries

Related:SentinelOne Targeted by North Korean IT Workers, Ransomware Groups, Chinese Hackers

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar as we explore why exploitation is outpacing remediation, where risk is growing fastest, and what security leaders can do to close the gap before attackers take advantage.

Register

CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps!

Register

People on the Move

Jazz has named Sean Robinson, Rickie Goyal, Danielle Guetta, Shani Nago, and Lior Magram as VPs and Michael Calev as COO.

AJ Shipley has been appointed Chief Product Officer at CrowdStrike.

Brinqa has named Ron Dovich as Chief AI and Automation Officer, David Allen as CTO, Steve Biagioni as CFO, and James Walta as VP of Product.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.