Chinese Hackers Exploit Google Calendar in Global Cyberattack

A sophisticated new breach highlights critical vulnerabilities in U.S.-based cloud platforms—this time using Google Calendar as a command-and-control tool.
In October 2024, cybercriminals linked to China used a novel method to infiltrate computers worldwide—by exploiting Google Calendar. According to the official blog of Google Cloud Threat Intelligence, the attackers targeted both private firms and government institutions, using calendar entries to control infected machines.
The technique involved sending a ZIP file via email, containing a disguised LNK file (posing as a PDF) and a directory. Once opened, the victim’s system was infected with components of a Trojan named TOUGHPROGRESS. The malware then connected to Google Calendar, executing commands embedded in scheduled events.
This approach created encrypted traffic between hackers and their targets, making detection extremely difficult. The Trojan integrated directly into system processes, bypassing conventional security tools. Experts say the attack demonstrates just how fragile major cloud platforms remain in the face of evolving threats.