PULSE NAME
APT41's "ToughProgress" Malware Abuses Google Calendar for C2 Evasion
WHITE Winnti Group PetrP.73 2025-05-31 Modified: 2025-05-31
77
IOCs
HIGH VOLUME
This pulse details APT41's (Winnti Group) new "ToughProgress" malware, which weaponizes Google Calendar for stealthy command-and-control (C2) communications. Key highlights from SOCRadar's analysis: Legitimacy Abuse: Uses Google Calendar events to hide malicious commands in seemingly benign public calendar entries. Multi-Stage Execution: Delivers PowerShell scripts to fetch encrypted payloads, bypassing traditional network defences. Persistence Mechanisms: Establishes footholds via scheduled tasks, registry modifications, and DLL sideloading. Targeted Evasion: Avoids sandboxes and leverages trusted cloud services to evade detection. IOCs Provided: Includes malware hashes, C2 domains, and behavioural patterns for hunting.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
ToughProgress
Indicators of Compromise (4 / 77 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 hostname domain URL
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 1ca609e207edb211c8b9566ef35043b6 2025-05-31
FileHash-MD5 2ec4eeeabb8f6c2970dcbffdcdbd60e3 MD5 of 151257e9dfda476cdafd9983266ad3255104d72a66f9265caa8417a5fe1df5d7 2025-05-31
FileHash-MD5 65da1a9026cf171a5a7779bc5ee45fb1 MD5 of 3b88b3efbdc86383ee9738c92026b8931ce1c13cd75cd1cda2fa302791c2c4fb 2025-05-31
FileHash-MD5 876fb1b0275a653c4210aaf01c2698ec MD5 of 469b534bec827be03c0823e72e7b4da0b84f53199040705da203986ef154406a 2025-05-31