Register to stream ATT&CKcon 2.0 October 29-30

CALENDAR

CALENDAR is malware used by APT1 that mimics legitimate Gmail Calendar traffic. [1]

ID: S0025
Type: MALWARE
Platforms: Windows
Version: 1.1

Techniques Used

Domain ID Name Use
Enterprise T1059 Command-Line Interface CALENDAR has a command to run cmd.exe to execute commands. [2]
Enterprise T1102 Web Service The CALENDAR malware communicates through the use of events in Google Calendar. [1] [2]

Groups That Use This Software

ID Name References
G0006 APT1 [1]

References