The sub-techniques beta is now live! Read the release blog post for more info.


CALENDAR is malware used by APT1 that mimics legitimate Gmail Calendar traffic. [1]

ID: S0025
Platforms: Windows
Version: 1.1
Created: 31 May 2017
Last Modified: 30 January 2019

Techniques Used

Domain ID Name Use
Enterprise T1059 Command-Line Interface

CALENDAR has a command to run cmd.exe to execute commands.[2]

Enterprise T1102 Web Service

The CALENDAR malware communicates through the use of events in Google Calendar.[1][2]

Groups That Use This Software

ID Name References
G0006 APT1 [1]