Cybersecurity researchers have identified a new, sophisticated command and control framework that exploits legitimate Google Calendar APIs to create covert communication channels between attackers and compromised systems.
The MeetC2 framework, discovered in September 2025, represents a worrying evolution in attacker tactics, where malicious users are exploiting trusted cloud services to bypass traditional security checks and evade detection mechanisms.
See also: Gemini exploit via Google Calendar to steal emails

The framework works by pretending that malicious traffic is normal business communications via Google’s widely trusted domains, specifically “oauth2.googleapis.com” and “www.googleapis.com.” This approach allows malicious activity to blend seamlessly with organizations’ normal traffic, making detection significantly more difficult for security teams. Interoperability across macOS and Linux platforms further enhances its potential impact across a variety of business environments.
Deriv Tech researchers noted that the framework design demonstrates a sophisticated understanding of modern security architectures and cloud service abuse techniques. The proof-of-concept implementation highlights how easily attackers can exploit legitimate SaaS platforms for malicious purposes, taking advantage of the inherent trust that organizations have in large cloud providers.
The attack methodology centers around a polling-based communication system, where compromised agents send GET requests every 30 seconds to specific Google Calendar API endpoints. When operators need to issue commands, they create calendar events with embedded instructions in the summary field, formatted as “Meeting from no one: [COMMAND]”. The victim agent detects these command events during regular polling cycles, extracts the commands, executes them locally, and updates the same calendar event with the execution results embedded within the [OUTPUT] [/OUTPUT] parameters in the description field.
See also: APT41 – ToughProgress malware: Abuse of Google Calendar for C2 purposes

The technical architecture of the MeetC2 framework reveals sophisticated obfuscation capabilities that exploit the ubiquity and trusted nature of Google services. The authentication process uses standard OAuth2, requiring attackers to create legitimate Google Cloud Console and service accounts with calendar access permissions. This approach ensures that all communications appear as authorized API interactions rather than suspicious network traffic.
The implementation requires minimal infrastructure, operating entirely through the existing Google Calendar API infrastructure. Operators authenticate through service accounts configured with “Change Events” permissions on shared calendars. The polling mechanism uses a 30-second interval, striking a balance between operational responsiveness and avoiding excessive API requests that can cause rate limits or suspicious activity alerts. Code execution is accomplished by extracting commands from calendar event summaries, with the results being pushed back into the description field of the same event. This bidirectional communication model creates a full command and control channel, maintaining the appearance of legitimate calendar sync activity.
See also: Google Calendar may soon save you time

The framework supports targeted command execution using host- specific syntax such as “ exec @host:command ” or broadcasting commands to multiple compromised systems simultaneously. MeetC2’s persistence and obfuscation features make it particularly concerning for enterprise security teams, as the framework does not create suspicious network patterns and exploits services that organizations have explicitly enabled for business operations .
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
