← Back to Pulse Feed
PULSE DETAIL
PULSE NAME
APT41's "ToughProgress" Malware Abuses Google Calendar for C2 Evasion
This pulse details APT41's (Winnti Group) new "ToughProgress" malware, which weaponizes Google Calendar for stealthy command-and-control (C2) communications. Key highlights from SOCRadar's analysis:
Legitimacy Abuse: Uses Google Calendar events to hide malicious commands in seemingly benign public calendar entries.
Multi-Stage Execution: Delivers PowerShell scripts to fetch encrypted payloads, bypassing traditional network defences.
Persistence Mechanisms: Establishes footholds via scheduled tasks, registry modifications, and DLL sideloading.
Targeted Evasion: Avoids sandboxes and leverages trusted cloud services to evade detection.
IOCs Provided: Includes malware hashes, C2 domains, and behavioural patterns for hunting.
MITRE ATT&CK & Malware Families
Indicators of Compromise (4 / 77 total)
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| FileHash-MD5 | 1ca609e207edb211c8b9566ef35043b6 | — | 2025-05-31 | |
| FileHash-MD5 | 2ec4eeeabb8f6c2970dcbffdcdbd60e3 | MD5 of 151257e9dfda476cdafd9983266ad3255104d72a66f9265caa8417a5fe1df5d7 | 2025-05-31 | |
| FileHash-MD5 | 65da1a9026cf171a5a7779bc5ee45fb1 | MD5 of 3b88b3efbdc86383ee9738c92026b8931ce1c13cd75cd1cda2fa302791c2c4fb | 2025-05-31 | |
| FileHash-MD5 | 876fb1b0275a653c4210aaf01c2698ec | MD5 of 469b534bec827be03c0823e72e7b4da0b84f53199040705da203986ef154406a | 2025-05-31 |