NewsBytes
    Hindi Tamil Telugu
    More
    In the news
    Narendra Modi
    Amit Shah
    Box Office Collection
    Bharatiya Janata Party (BJP)
    OTT releases
    Hindi Tamil Telugu
    NewsBytes
    User Placeholder

    Hi,

    Logout

    India
    Business
    World
    Politics
    Sports
    Technology
    Entertainment
    Auto
    Lifestyle
    Inspirational
    Career
    Bengaluru
    Delhi
    Mumbai

    Download Android App

    Follow us on
    • Facebook
    • Twitter
    • Linkedin
    Home / News / Technology News / Attention! This new malware may target your Google Calendar data
    Summarize
    Next Article
    Attention! This new malware may target your Google Calendar data
    The malware is called TOUGHPROGRESS and it can exploit Google Calendar

    Attention! This new malware may target your Google Calendar data

    By Akash Pandey
    May 29, 2025
    04:44 pm

    What's the story

    The notorious Chinese hacking group APT41, also known as Winnti, Brass Typhoon, and Wicked Panda, is using a new malware called TOUGHPROGRESS to exploit Google Calendar.

    The revelation was made by Google's Threat Intelligence Group (GTIG) after the campaign was discovered in October 2024.

    The attack targeted several government entities via a compromised government website.

    Infection details

    Malware's infection process

    The TOUGHPROGRESS malware is spread through spear-phishing emails that lead victims to a malicious ZIP archive on a compromised government website.

    This archive contains a Windows shortcut file (LNK) disguised as a PDF and a folder of fake images named after arthropod photos.

    When the LNK is clicked, it starts a multi-stage infection process involving PLUSDROP, PLUSINJECT, and TOUGHPROGRESS itself.

    Operational details

    TOUGHPROGRESS's operation and previous misuse

    The TOUGHPROGRESS malware operates by using Google Calendar events for data exfiltration and command reception.

    It creates and modifies events, including zero-minute ones with embedded data on certain hard-coded dates. These are then polled and executed on the infected host.

    This isn't the first time APT41 has misused Google's infrastructure. In 2023, they used Google Drive to deliver a backdoor called Google Command and Control (GC2), which read commands from Google Sheets and exfiltrated data.

    Response measures

    Google's response and protection tips

    In response to the threat, Google has shut down the malicious Calendar and related Workspace projects to neutralize the campaign.

    The company has also alerted affected organizations about the breach. However, the full extent of the intrusion remains unknown.

    To stay protected from such attacks, users are advised not to open links or attachments from unknown sources and to disable LNK file previews in Windows.

    Also, they should use updated antivirus, endpoint detection tools, and regularly monitor cloud service access/permissions.

    Facebook
    Whatsapp
    Twitter
    Linkedin
    Related News
    Latest
    Malware
    Google Calendar
    Google
    Cybercrimes

    Latest

    Attention! This new malware may target your Google Calendar data Malware
    Woman attacks boy inside plane for calling her 'Miss Piggy'  United States of America
    'Not one..completed on time': IAF chief flags defense project delays Indian Air Force
    NVIDIA reports $44B Q1 revenue—beats expectations amid China export restrictions AMD

    Malware

    Android users beware! Delete these 8 malicious apps immediately Android
    Beware! These malicious apps can harm your Android smartphone Android
    Beware, Android smartphone users! GB WhatsApp may contain malware WhatsApp
    Cybercrimes surged in 2022; crypto, malware attacks led the way Cybercrimes

    Google Calendar

    Google working on redesigning Gmail for web Gmail
    Google to bring self-destructing emails in new Gmail Gmail
    Google launches new to-do app called Google Tasks Google
    Google's online tool for building business apps becomes available Google

    Google

    US victims of explicit deepfakes can soon sue creators  Meta
    Microsoft just made it free to publish your app Apple
    Google just dropped an AI research app for your smartphone  Android
    Google I/O starts today—How to watch and what to expect Microsoft

    Cybercrimes

    Amitabh Bachchan unites with 'Panchayat' cast to raise cybercrime awareness Amitabh Bachchan
    India witnesses 44% more weekly cyberattacks than rest of world India
    UnitedHealth says 190M Americans were impacted by data breach Cybersecurity
    DeepSeek AI suspends new sign-ups following major cyberattack ChatGPT
    Indian Premier League (IPL) Celebrity Hollywood Bollywood UEFA Champions League Tennis Football Smartphones Cryptocurrency Upcoming Movies Premier League Cricket News Latest automobiles Latest Cars Upcoming Cars Latest Bikes Upcoming Tablets
    About Us Privacy Policy Terms & Conditions Contact Us Ethical Conduct Grievance Redressal News News Archive Topics Archive Download DevBytes Find Cricket Statistics
    Follow us on
    Facebook Twitter Linkedin
    All rights reserved © NewsBytes 2025