Skip to content


CALENDAR is malware used by APT1 that mimics legitimate Gmail Calendar traffic. 1

Item Value
ID S0025
Associated Names
Version 1.2
Created 31 May 2017
Last Modified 30 March 2020
Navigation Layer View In ATT&CK® Navigator

Techniques Used

Domain ID Name Use
enterprise T1059 Command and Scripting Interpreter -
enterprise T1059.003 Windows Command Shell CALENDAR has a command to run cmd.exe to execute commands.2
enterprise T1102 Web Service -
enterprise T1102.002 Bidirectional Communication The CALENDAR malware communicates through the use of events in Google Calendar.12

Groups That Use This Software

ID Name References
G0006 APT1 1


Back to top