Google Calendar RAT (GCR) is a proof of concept for Command & Control (C2) via Google Calendar Events. It’s useful when setting up a full red team infrastructure is challenging.
GCR needs a Gmail account, using event descriptions in Google Calendar as a “Covert Channel” for direct connections to Google. Besides this, it acts as a layer 7 application called Covert Channel, as reported by its developer and researcher, Mr. Saighnal (aka Valerio Alessandroni).
When GCR is running on a computer that has been hacked, it checks the calendar event description for new commands every so often. It then runs those commands on the target device and adds the results of the commands to the event description. Based on what the coder said, GCR only talks through official Google infrastructure, which makes it hard for defenders to spot strange behavior, Google said.
The red teaming tool uses Google Calendar events for C2. The tool enables an attacker to place commands in the event description field of Google Calendar events.
GCR connects to a shared Google Calendar link, checks for pending commands, and creates a new one “whoami” if none exist.
In the below image, the complete GCR workflow attack is presented:
While apart from this, each event consists of two parts, and here we have mentioned them:-
Moreover, the connections appear to be completely genuine because they are limited to Google’s servers in terms of networking.
Ensure your Cyber Resiliance with the recent wave of cyber-attacks targeting the financial services sector. Almost 60% respondents not confident to recover fully from a cyber attack.
Here below, we have mentioned all the steps to use it:-
=> CLEAR_COMMAND|BASE64_OUTPUT
Earlier, Google TAG noticed an Iran-linked APT group using Gmail for C2 with a small .NET backdoor, BANANAMAIL, in March 2023. Besides this, through IMAP the backdoor checks email accounts for the execution of commands.
We haven’t seen GCR used in real life yet, but Mandiant has seen multiple players share the public proof of concept on underground sites. Google said via a threat report that people are still interested in abusing cloud services.
Patch Manager Plus: Automatically Patch over 850 third-party applications quickly – Try Free Trial.
Also Read:
A New Malware That Hides In The Linux Calendar System on February 31st
Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…
The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…
CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…
Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…
You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…
Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…