CALENDAR

S0025

Malware.View on attack.mitre.org

About this malware

CALENDAR is malware used by APT1 that mimics legitimate Gmail Calendar traffic.

Techniques used2

Procedure examples2

TechniqueProcedure example
T1059.003
Windows Command Shell

CALENDAR has a command to run cmd.exe to execute commands.

T1102.002
Bidirectional Communication

The CALENDAR malware communicates through the use of events in Google Calendar.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Mandiant APT1 Open source
    Mandiant. (n.d.). APT1 Exposing One of China’s Cyber Espionage Units. Retrieved July 18, 2016.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.