HomeSecurityTA415 uses Google Sheets & Calendar for C2 communications

TA415 uses Google Sheets & Calendar for C2 communications

The Chinese hacking group TA415 has evolved its tactics, techniques, and procedures, leveraging legitimate cloud services like Google Sheets and Google Calendar for command and control communications. These changes have been identified in recent campaigns targeting the U.S. government, think tanks, and academic institutions.

TA415 Google Sheets & Calendar

During July and August 2025, this sophisticated group conducted spear-phishing attacks using baits themed around US-China economic relations. The emails appeared to come from prominent figures, including the current Chairman of the Committee on Strategic Competition between the United States and the Chinese Communist Party.

The tactics of TA415, also known as APT41, Brass Typhoon, and Wicked Panda, represent a significant shift in state-sponsored cyber operations, abandoning traditional malware delivery mechanisms in favor of legitimate deployment tools.

See also: Python-based XillenStealer attacks Windows users

The group's latest campaigns have used trusted services for their command and control infrastructure, demonstrating a deliberate strategy to merge malicious activity with normal network traffic patterns. This approach significantly complicates detection efforts, as security tools must distinguish between legitimate business communications and "hostile" command channels.

Proofpoint researchers found that TA415’s recent operations have focused primarily on gathering information about the state of U.S.-China economic relations, aligned with broader geopolitical tensions and ongoing trade negotiations. The timing of these campaigns coincides with critical policy discussions surrounding U.S.-Taiwan relations and comprehensive sanctions frameworks targeting China, suggesting targeted intelligence seeking by key state actors.

TA415 uses Google Sheets & Calendar for C2 communications

The infection method involves delivering files password-protected via cloud sharing services such as Zoho WorkDrive, Dropbox, and OpenDrive. These files contain Microsoft shortcut files along with hidden assets stored in hidden MACOS subfolders. The group consistently uses Cloudflare WARP VPN services to hide sender IP addresses during email delivery, adding an extra layer of operational security to their campaigns.

See also: Over 40,000 cyberattacks target API environments

TA415: Advanced chain of infection

The TA415 infection mechanism demonstrates a sophisticated understanding of legitimate development workflows through the deployment of Visual Studio Code Remote Tunnels. When executed, the malicious LNK file triggers a batch script named logon.bat, which then launches the WhirlCoil Python loader via a built-in Python package. This loader exhibits advanced obfuscation techniques using repeated variable and function names (IIIllIIIIlIlIIlIII) to evade static analysis detection methods.

The WhirlCoil component downloads the VSCode Command Line Interface from official Microsoft sources, extracts it to %LOCALAPPDATA%\Microsoft\VSCode, and establishes persistence via scheduled tasks named GoogleUpdate, GoogleUpdated, or MicrosoftHealthcareMonitorNode. The script runs the command code.exe tunnel user login –provider github –name to create GitHub-authenticated remote tunnels, providing persistent access without conventional malware signatures.

TA415 uses Google Sheets & Calendar for C2 communications

System information collection includes Windows version details, local language settings, computer identification, username, and domain information, transmitted via POST requests to free request logging services.

See also: Microsoft OneDrive Auto-Sync exposes data in SharePoint Online

The extracted data is combined with VS Code Remote Tunnel verification codes, allowing threat actors to authenticate remote sessions and execute arbitrary commands through Visual Studio's integrated terminal interface.

The use of legitimate services for covert information mining highlights a worrying shift in cyberattacks: attackers are merging malicious infrastructure with everyday network traffic, making detection more difficult. This requires organizations and researchers to shift to behavioral monitoring, stricter management of third-party services, and international cooperation — as attacks now reflect broader geopolitical and intelligence interests. In addition, investment in staff training, rapid response procedures, and a clear legal framework is required.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS