Hackers have reportedly found a way to use the Google Calendar as command & control (C2) infrastructure which could create quite a few headaches in the cybersecurity community.

    • jimbolauski@lemmy.world
      link
      fedilink
      English
      arrow-up
      8
      arrow-down
      1
      ·
      2 years ago

      They are encoding commands in calendar events there is not a vulnerability in Google calendar. After your device is compromised its commanded to subscribe to a calendar. Those events have commands. Since checking your calendar is a normal event unlike connecting to a nefarious server it becomes more difficult to discover.

        • halcyoncmdr@lemmy.world
          link
          fedilink
          English
          arrow-up
          1
          ·
          2 years ago

          I mean security through obscurity is a real thing. It’s not real security, but the risk of attack is still lower than it would be otherwise. It’s the primary reason Macs had so little malware at the time and Apple’s marketing leveraged that for billions in advertising. Generally malware creators target the maximum number of devices, and MacOS and ChromeOS are small pickles compared to Windows. Even now, you’re looking at Windows being about 70% of the market, OSX being around 20% and Chrome OS sitting at a whopping 4%. Most malware is based around striking as many victims as possible quickly before it is discovered and the exploits patched. doesn’t matter.