Revealed: Chinese Hackers Weaponize Google Calendar as Covert Command Center


# Chinese State Hackers Exploit Google Calendar for Covert Operations

Google’s Threat Intelligence Group has uncovered a sophisticated cyber espionage operation by Chinese state-sponsored threat actor APT41. Discovered in late October 2024, the attack leverages a malware called TOUGHPROGRESS that uniquely uses Google Calendar for command-and-control communications.

## Attack Methodology

The attack begins with spear-phishing emails containing links to a ZIP archive hosted on a compromised government website. This archive includes:
– A Windows shortcut (LNK) disguised as a PDF document
– A directory with seven apparent arthropod images, though “6.jpg” and “7.jpg” are actually malicious files

When victims click the LNK file, they see a decoy PDF claiming the species need export declaration, while the malware silently deploys in three stages:

1. **PLUSDROP**: A DLL that decrypts and executes the next payload in memory
2. **PLUSINJECT**: Launches and hollows a legitimate “svchost.exe” process to inject the final payload
3. **TOUGHPROGRESS**: The primary malware that uses Google Calendar for command-and-control

## Google Calendar Exploitation

The malware creates zero-minute calendar events with a hard-coded date (2023-05-30) to store stolen data in event descriptions. Attackers place encrypted commands in Calendar events dated July 30-31, 2023, which the malware polls, decrypts, and executes, writing results back to Calendar events for extraction.

Google has terminated the malicious Calendar account and associated Workspace projects, effectively neutralizing the campaign, and has notified affected organizations.

## APT41 Background

APT41 (also known as Axiom, Brass Typhoon, Winnti, and other aliases) has a history of targeting governments and organizations in shipping, media, technology, and automotive sectors globally. Earlier in 2024, the group conducted campaigns against entities in Italy, Spain, Taiwan, Thailand, Turkey, and the UK, as well as Japanese manufacturing companies.

This isn’t APT41’s first abuse of Google services—in April 2023, they targeted a Taiwanese media organization using Google Drive and Google Sheets for command-and-control operations.

Share This Article