Google Calendar as C2 infrastructure: a China-nexus campaign with stealthy tactics

No ratings

Presented at VB2025 Berlin by

In recent years, China-nexus threat groups have increasingly adopted tactics to obscure their malware footprint, particularly through the use of LOTS (living off trusted sites) and LOLBins (living off the land binaries and scripts). Our latest research has uncovered a new malware variant named Calendarwalk. Calendarwalk employs tactics not previously observed within the APT landscape, such as abusing LOTS through Google Calendar events and exploiting LOLBins via Windows Workflow Foundation. In this talk, we will examine Calendarwalk and the unique techniques it employs, followed by an analysis of its connection to APT41 based on our findings