{"id":259244,"date":"2023-11-07T10:01:26","date_gmt":"2023-11-07T15:01:26","guid":{"rendered":"https:\/\/sftarticles.wpenginepowered.com\/es\/?p=313879"},"modified":"2025-07-01T17:44:14","modified_gmt":"2025-07-02T00:44:14","slug":"not-even-google-calendar-is-free-from-hackers","status":"publish","type":"post","link":"https:\/\/cms-articles.softonic.io\/en\/not-even-google-calendar-is-free-from-hackers\/","title":{"rendered":"Even Google Calendar is not spared from hackers"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">As reported by Google itself (<a href=\"https:\/\/thehackernews.com\/2023\/11\/google-warns-of-hackers-absing-calendar.html\" target=\"_blank\" rel=\"noopener nofollow\" title=\"\">via TheHackerNews<\/a>), it appears that Google Calendar has now become <strong>a service of potential interest to hackers<\/strong>, although it doesn&#8217;t seem like they are making much use of it at the moment. To be more specific, those at Mountain View have recently shared a warning about <strong>the existence of various threat actors who are sharing a proof of concept (PoC) of a public exploit <\/strong>that takes advantage of the mentioned Calendar <strong>to host a command and control (C2) infrastructure<\/strong>.<\/p>\n\n\n<div class=\"sc-card-program\">\r\n  <div class=\"sc-card-program__body\">\r\n    <div class=\"sc-card-program__row clearfix\">\r\n      <div class=\"sc-card-program__col-logo\">\r\n        <img decoding=\"async\" class=\"sc-card-program__img\" src=\"https:\/\/images.sftcdn.net\/images\/t_app-icon-s\/p\/f21f4cc4-91ef-11e6-86ad-00163ec9f5fa\/1742340490\/google-calendar-logo.jpg\" alt=\"Google Calendar\" width=\"100px\" height=\"100px\">\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-title\">\r\n        <span class=\"sc-card-program__title\">Google Calendar<\/span>\r\n        <a class=\"sc-card-program__button sc-card-program-internal\" href=\"https:\/\/google-calendar.en.softonic.com\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">DOWNLOAD<\/a>\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-rating\">\r\n        <svg class=\"rating-score__content\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" version=\"1.1\" x=\"0\" y=\"0\" viewbox=\"0 0 50 50\" enable-background=\"new 0 0 50 50\" xml:space=\"preserve\"><path class=\"rating-score__background rating-score--good\" fill=\"none\" stroke-width=\"6\" stroke-miterlimit=\"10\" d=\"M40 40c8.3-8.3 8.3-21.7 0-30s-21.7-8.3-30 0 -8.3 21.7 0 30\"><\/path><path class=\"rating-score__value rating-score__value--0\" fill=\"none\" stroke-width=\"6\" stroke-dashoffset=\"0\" stroke-miterlimit=\"10\" d=\"M40 40c8.3-8.3 8.3-21.7 0-30s-21.7-8.3-30 0 -8.3 21.7 0 30\"><\/path><text class=\"rating-score__number\" content=\"\" text-anchor=\"middle\" transform=\"matrix(1 0 0 1 25 31.0837)\" data-auto=\"app-user-score\"><\/text><\/svg>\r\n      <\/div>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <span class=\"sc-card-program__description\"><\/span>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <img decoding=\"async\" class=\"sc-card-program__bigpic\" src=\"\" onerror=\"this.style.display='none'\">\r\n    <\/div>\r\n    <a class=\"sc-card-program__link track-link sc-card-program-sponsored\" href=\"https:\/\/google-calendar.en.softonic.com\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\"><\/a>\r\n  <\/div>\r\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">The tool we mentioned, which appears to be circulating on the deep web, is called <strong>&#8220;Google Calendar RAT&#8221; (GCR). It uses events to establish a C2 communication through a Gmail account<\/strong>. According to the person responsible for this threat, who goes by the name MrSaighnal, this script can <strong>create a &#8220;covert channel&#8221; by exploiting event descriptions in Google Calendar. This allows the attacker to establish a direct connection through Google<\/strong>, as stated by the threat actor. Therefore, with this tool, it is very challenging for security teams to detect the threat.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Google Calendar can become an important tool for hackers<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">This GCR works by having <strong>the compromised machine periodically check the event descriptions in Google Calendar for new commands<\/strong>. When these commands are identified, they are executed on the respective device, as reported by Google itself. Additionally, it is mentioned that once the command is executed, <strong>the event description is updated with the output of the said command<\/strong>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">As mentioned earlier, it appears that <strong>this GCR has not been used as of today, at least according to Google&#8217;s information<\/strong>. However, with this circulating on the internet, it seems to be only a matter of time before someone attempts to exploit it. In fact, Mandiant&#8217;s threat intelligence unit <strong>has already detected that this tool has been shared through underground forums<\/strong>.<\/p>\n\n\n<div class=\"sc-card-program\">\r\n  <div class=\"sc-card-program__body\">\r\n    <div class=\"sc-card-program__row clearfix\">\r\n      <div class=\"sc-card-program__col-logo\">\r\n        <img decoding=\"async\" class=\"sc-card-program__img\" src=\"https:\/\/images.sftcdn.net\/images\/t_app-icon-s\/p\/f21f4cc4-91ef-11e6-86ad-00163ec9f5fa\/1742340490\/google-calendar-logo.jpg\" alt=\"Google Calendar\" width=\"100px\" height=\"100px\">\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-title\">\r\n        <span class=\"sc-card-program__title\">Google Calendar<\/span>\r\n        <a class=\"sc-card-program__button sc-card-program-internal\" href=\"https:\/\/google-calendar.en.softonic.com\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">DOWNLOAD<\/a>\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-rating\">\r\n        <svg class=\"rating-score__content\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" version=\"1.1\" x=\"0\" y=\"0\" viewbox=\"0 0 50 50\" enable-background=\"new 0 0 50 50\" xml:space=\"preserve\"><path class=\"rating-score__background rating-score--good\" fill=\"none\" stroke-width=\"6\" stroke-miterlimit=\"10\" d=\"M40 40c8.3-8.3 8.3-21.7 0-30s-21.7-8.3-30 0 -8.3 21.7 0 30\"><\/path><path class=\"rating-score__value rating-score__value--0\" fill=\"none\" stroke-width=\"6\" stroke-dashoffset=\"0\" stroke-miterlimit=\"10\" d=\"M40 40c8.3-8.3 8.3-21.7 0-30s-21.7-8.3-30 0 -8.3 21.7 0 30\"><\/path><text class=\"rating-score__number\" content=\"\" text-anchor=\"middle\" transform=\"matrix(1 0 0 1 25 31.0837)\" data-auto=\"app-user-score\"><\/text><\/svg>\r\n      <\/div>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <span class=\"sc-card-program__description\"><\/span>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <img decoding=\"async\" class=\"sc-card-program__bigpic\" src=\"\" onerror=\"this.style.display='none'\">\r\n    <\/div>\r\n    <a class=\"sc-card-program__link track-link sc-card-program-sponsored\" href=\"https:\/\/google-calendar.en.softonic.com\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\"><\/a>\r\n  <\/div>\r\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">Google Calendar joins other legitimate services as a way for hackers to distribute malware, similar to the case of <a href=\"https:\/\/en.softonic.com\/articles\/google-docs-tricks-create-attractive-covers?ex=RAMP-1114.4\" target=\"_blank\" rel=\"noopener\" title=\"\">Google Docs<\/a>. Google Docs has a sharing function <strong>that allows users to enter an email address in the document, notifying the recipient that they have access to the file<\/strong>. In fact, it has been observed that <strong>malicious links were embedded in files and distributed through users&#8217; email inboxes<\/strong>. Since these emails came from Google, <strong>many users bypassed email protection services<\/strong>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>As reported by Google itself (via TheHackerNews), it appears that Google Calendar has now become a service of potential interest to hackers, although it doesn&#8217;t seem like they are making much use of it at the moment. To be more specific, those at Mountain View have recently shared a warning about the existence of various &hellip; <a href=\"https:\/\/cms-articles.softonic.io\/en\/not-even-google-calendar-is-free-from-hackers\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;Even Google Calendar is not spared from hackers&#8221;<\/span><\/a><\/p>\n","protected":false},"author":9280,"featured_media":259246,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","wpcf-pageviews":4},"categories":[1015],"tags":[4729],"usertag":[],"vertical":[],"content-category":[],"class_list":["post-259244","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","tag-google-calendar"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/259244","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/users\/9280"}],"replies":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/comments?post=259244"}],"version-history":[{"count":1,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/259244\/revisions"}],"predecessor-version":[{"id":316624,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/259244\/revisions\/316624"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/media\/259246"}],"wp:attachment":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/media?parent=259244"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/categories?post=259244"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/tags?post=259244"},{"taxonomy":"usertag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/usertag?post=259244"},{"taxonomy":"vertical","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/vertical?post=259244"},{"taxonomy":"content-category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/content-category?post=259244"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}