Domain | ID | Name | Use | |
---|---|---|---|---|
Enterprise | T1059 | .003 | Command and Scripting Interpreter: Windows Command Shell |
CALENDAR has a command to run cmd.exe to execute commands.[2] |
Enterprise | T1102 | .002 | Web Service: Bidirectional Communication |
The CALENDAR malware communicates through the use of events in Google Calendar.[1][2] |
ID | Name | References |
---|---|---|
G0006 | APT1 |