Google Calendar as a Command-and-Control Channel
Google Calendar RAT (GCR) routes attacker commands through Google Calendar events. An agent deployed on the target machine polls the calendar. Commands go in the event title (up to 1,024 characters) or description (over 8,000 characters), and output comes back Base64-encoded in the same field with a pipe as separator. Setup requires a service account, the Calendar API enabled, and a shared calendar. No direct connection between attacker and target is ever established.
APT41 Adopts the Same Technique
Google’s Cybersecurity Action Team mentioned GCR in its Threat Horizons report shortly after the 2023 release. Then in April 2025, APT41 deployed malware called ToughProgress using the same technique. The link is concrete: Alessandroni had hardcoded an event creation date of May 30, 2023 as an IOC inside GCR. The Google report showed APT41’s ToughProgress using that exact same date, indicating the threat actor built their tool on GCR’s code.
GSOX: SOCKS5 Proxy Tunneled Through Google Sheets
GCR and similar tools are limited to synchronous request-response. GSOX removes that constraint by acting as a SOCKS5 proxy server, written in Go. The client runs on the attacker machine and listens on port 9191. Proxychains routes traffic through that port, over Google Sheets rows, to an agent on the target. The Sheets model uses columns for socket ID, client/server label, timestamp, and payload. Each cell holds up to 5,000 characters; Base64 encoding adds 33% overhead. Any service reachable from the target becomes reachable through the proxy.
Performance After Optimization and Network Evasion
Initial tests showed PSExec needed 20 minutes and secretsdump 15 minutes to complete. Splitting the payload byte stream to respect the 5,000-character cell limit helped. The main gain came from a rotational account system that spreads API quota load. After optimization, PSExec dropped to 2 minutes and secretsdump to 1 minute. The demo used 3 accounts on the client and 4 on the server. Network traffic analysis shows only connections to Google infrastructure, so traffic inspection does not identify the channel.
Notable Quotes
have fun during the development. Valerio “MrSaighnal” Alessandroni · ▶ 1:48
So it works everything has been executed Valerio “MrSaighnal” Alessandroni · ▶ 13:55
started an appeal and uh I was surprised Valerio “MrSaighnal” Alessandroni · ▶ 15:23
Key Takeaways
- Google Calendar’s API serves as a covert C2 channel with no dedicated infrastructure required.
- APT41’s ToughProgress malware reused GCR code, confirmed by a hardcoded IOC date of May 30, 2023.
- GSOX tunnels arbitrary protocols through Google Sheets using a SOCKS5 proxy on port 9191.
About the Speaker(s)
Valerio “MrSaighnal” Alessandroni is a seasoned offensive security professional with a lifelong passion for hacking. A former member of the Italian Army’s cyber units, he now leads EY Italy’s Offensive Security team, focusing on advanced red teaming and threat emulation. He holds certifications including OSCP, OSEP, OSWE, OSWP, CRTO, eWPTX, and eCPTX. His bug bounty research has earned recognition from Microsoft, NASA, and Harvard. Off the keyboard, he trains Brazilian Jiu Jitsu and dreams of space exploration.