The APT41 nation-state threat group is exploiting yet another cloud service to mask its operations, according to new research.
Google discovered a malware variant it dubbed “ToughProgress” that uses Google Calendar as a command-and-control (C2) server, a novel way of establishing a communications link between APT41’s infrastructure and compromised devices that is both reliable and innocuous.
“Once executed, TOUGHPROGRESS creates a zero minute Calendar event at a hardcoded date, 2023-05-30, with data collected from the compromised host being encrypted and written in the Calendar event description,” Google researchers wrote.
“The operator places encrypted commands in Calendar events on 2023-07-30 and 2023-07-31, which are predetermined dates also hardcoded into the malware,” the researchers explained. “TOUGHPROGRESS then begins polling Calendar for these events. When an event is retrieved, the event description is decrypted and the command it contains is executed on the compromised host. Results from the command execution are encrypted and written back to another Calendar event.”
ToughProgress isn’t the first malware strain to exploit cloud services for C2 infrastructure. “Misuse of cloud services for C2 is a technique that many threat actors leverage in order to blend in with legitimate activity,” Google researchers wrote, pointing to similar episodes involving Microsoft , Dropbox and even Instagram .
The continued abuse of legitimate, high-profile cloud services presents a major challenge for security teams, which must monitor not only for suspicious connections (such as visits to malicious websites) but also nefarious activity occurring over legitimate connections.
The Chinese state-backed group APT41 is one of Beijing’s premier hacking teams. The group has used free services to host their payloads since at least last August, according to Google researchers, who observed the group sending links to these payloads “to hundreds of targets in a variety of geographic locations and industries.” APT41 is particularly fond of Cloudflare Worker web domains, according to the researchers.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
