By using this site, you agree to the Privacy Policy and Terms of Use.
Accept

The Morning News informer

Perfect for news, magazine, blog and for all kinds of publishing websites

  • Latest News
  • World News
    • America
    • China
    • Russia
    • UAE
    • Asia
  • All India News
    • South India
    • North India
    • Delhi
    • Mumbai
  • Sports
    • Cricket
      • T20 World Cup
      • IPL
    • Football
      • FiFA World Cup
    • World-cup
  • Entertainment
    • Celebrity
    • Movies
    • Movie Reviews
    • Travel
    • Special Events
    • Video Games
  • Technology
    • PC Hardware
    • Gadget
    • Tech News
    • Tech Reviews
  • Business & Finance
    • Business
    • Finance
    • Investment
    • Startup News
  • Health
    • Nutrition
    • Medicine
    • Beauty Tips
  • Life Styles
    • Fashion
    • Beauty Tips
    • Magazine
Reading: Google Shuts Down China-Linked Calendar Hack: APT41 Malware Exposed
Share
Facebook Youtube Tumblr Threads Telegram Whatsapp
Font ResizerAa
The Morning News InformerThe Morning News Informer
  • Latest News
  • World News
  • All India News
  • Sports
  • Entertainment
  • Technology
  • Business & Finance
  • Health
  • Life Styles
Search
  • Latest News
  • World News
    • America
    • China
    • Russia
    • UAE
    • Asia
  • All India News
    • South India
    • North India
    • Delhi
    • Mumbai
  • Sports
    • Cricket
    • Football
    • World-cup
  • Entertainment
    • Celebrity
    • Movies
    • Movie Reviews
    • Travel
    • Special Events
    • Video Games
  • Technology
    • PC Hardware
    • Gadget
    • Tech News
    • Tech Reviews
  • Business & Finance
    • Business
    • Finance
    • Investment
    • Startup News
  • Health
    • Nutrition
    • Medicine
    • Beauty Tips
  • Life Styles
    • Fashion
    • Beauty Tips
    • Magazine
Follow US
© 2025 The Morning News Informer. All Rights Reserved.
The Morning News Informer > Blog > Technology > Tech News > Google Shuts Down China-Linked Calendar Hack: APT41 Malware Exposed
Tech NewsTechnology

Google Shuts Down China-Linked Calendar Hack: APT41 Malware Exposed

Writer
Last updated: May 30, 2025 12:44 pm
Writer
Share
images 34
SHARE

Introduction

In a stunning revelation, Google has confirmed that state-sponsored hackers from China exploited Google Calendar to run a sophisticated cyber-espionage campaign. The operation, linked to the APT41 (also known as HOODOO) group, utilized Calendar events as a command-and-control (C2) channel to extract sensitive data from infected devices.

Contents
IntroductionDiscovery and AttributionHow the Malware WorkedGoogle Calendar as a Command ChannelGoogle’s Response and MitigationConclusion

Discovery and Attribution

China-linked hackers exploit Google Calendar in cyberattacks on governments  | The Record from Recorded Future News

According to Google Threat Intelligence Group (GTIG), the breach was discovered in October 2024 and traced to a compromised government website used to spread malware. The malware campaign, dubbed TOUGHPROGRESS, was carefully engineered and attributed to APT41 — a known Chinese advanced persistent threat actor listed in MITRE ATT&CK’s threat database.

How the Malware Worked

The infection process began with spear phishing emails targeting specific users. These emails contained a ZIP file hosted on the compromised website. The archive included a disguised shortcut (.LNK) file mimicking a PDF, and a folder of images showing insects and spiders. Hidden within two of these JPGs were:

  • An encrypted payload
  • A dynamic link library (DLL) to decrypt and execute it

When the user clicked the LNK file, it initiated a three-stage malware execution pipeline:

APT41 Taps Google Red-Teaming Tool in Targeted Info-Stealing Attacks
  1. Stage 1: Decrypt and run the PLUSDROP DLL in memory
  2. Stage 2: Launch a legitimate Windows process, then inject malicious code via process hollowing
  3. Stage 3: Deploy TOUGHPROGRESS to steal data and use Google Calendar as a C2 channel

Google Calendar as a Command Channel

TOUGHPROGRESS used zero-minute Calendar events with encrypted data in the event descriptions. Hardcoded dates like May 30, 2023, and July 30–31, 2023 served as triggers and backdoors for communication. When an attacker issued commands, TOUGHPROGRESS would scan the calendar, decrypt instructions, execute them, and send the results back via new calendar events — a novel and stealthy use of cloud services.

Google’s Response and Mitigation

GTIG responded swiftly by disabling attacker-controlled Calendar accounts, Google Workspace projects, and associated infrastructure. In addition, they:

  • Updated Google Safe Browsing to block malicious domains
  • Created custom malware detection signatures
  • Notified affected organizations and shared malware samples for forensic analysis
APT41 malware abuses Google Calendar for stealthy C2 communication

Conclusion

This incident is a stark reminder of how even trusted cloud-based productivity tools can be weaponized. While Google has taken decisive action to shut down APT41’s Calendar-based C2 system, the campaign highlights the need for vigilant cyber hygiene and better cloud app monitoring.

For more expert guidance on hardening your systems against APT groups, visit CISA’s Vulnerability Catalog.

TAGGED:apt41cloud app hackcyber espionage chinacyberattack 2025dll injectiongoogle calendar hackgoogle safe browsinggoogle threat intelgtigmalware c2malware via calendarplustdropprocess hollowingspear phishingtoughprogress malware
Share This Article
Email Copy Link Print
Share
Previous Article 1736579943 shutterstock 2472113547 750x500 1 Microsoft Secures Barclays AI Deal: 100K Copilot Licenses Signal Big AI Push
Next Article motorola g86 power pdp design ch Motorola G86, G86 Power & G56 Launched: Powerful Mid-Range Phones with Dimensity 7300
Leave a Comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Latest News

Oponion

Rain in city 6 1747792813454 1747792826961 1

Heavy Rainfall in Mumbai, Bengal; Thunderstorms Forecast for Delhi and South India: IMD Alert

The India Meteorological Department (IMD) has issued a high-alert weather…

May 31, 2025
why india grounding turkish aviation firm celebi is a seismic security shift 184734642 16x9 0

India Blocks Turkish Firm Çelebi on Security Grounds: No Explanation Given

Introduction In a significant development with geopolitical implications, the Indian…

June 3, 2025
article

2 Terrorists Linked to 2023 Pune Conspiracy Arrested in Mumbai

Introduction The National Investigation Agency (NIA) has apprehended two operatives…

June 1, 2025
images 41

Ukraine and Russia Hold First Direct Talks Since 2022, Agree on 1,000 Prisoner Swap

For the first time in over three years, Ukrainian and…

July 20, 2025
freepik export 20240501163758a0i6

Top 6 Ways AI Reduces Workplace Burnout and Boosts Productivity

Introduction Workplace burnout is more than a buzzword—it's a growing…

July 20, 2025
Previous Next
The Morning news informer

Perfect for news, magazine, blog and for all kinds of publishing websites

News

Latest News

World News

India News

International Affairs

Sports

Cricket

Football

T20 World Cup

IPL

Technology

Tech News

Gadget

PC Hardware

Innovate

Entertainment

Movies

Celebrity News

Screen Entertainment

Videos Games

Health & Lifestyle

Health & Lifestyle

Nutrition

Beauty Tips

Children

Business

Business

Finance

Investment

Startup News

Privacy Policy

Cookie Policy

Terms And Conditions

Contact US

Facebook Youtube Tumblr Threads Telegram Whatsapp

© The Morning News Infomer. All Rights Reserved

Go to mobile version
Username or Email Address
Password

Lost your password?