Fake Calendar Invites Push Malware Past Email Defenses
Sublime Security tracked sharp month-over-month growth in ICS phishing, where malicious calendar invitations exploit default settings in Outlook, Gmail and Apple Mail.

Calendar-based malware attacks surged through the summer as phony meeting invitations used a trusted workflow to land directly in users’ schedules, ZDNET reported, citing new research from Sublime Security.
The campaign turns the ordinary ICS calendar file into a delivery path for phishing and remote-access malware.
Sublime recorded month-over-month increases of 282 percent in June, 338 percent in July and 1,216 percent in August, with September projected to rise another 2,852 percent over August.
The technique works because calendar invitations often move through mail systems differently from ordinary messages.
Microsoft Outlook, Gmail and Apple Mail can add an emailed invitation to a calendar before the recipient accepts or declines it.
That puts a malicious event on a user’s schedule even when the person never intended to interact with the sender.
Sublime calls the tactic ICS phishing, after the iCalendar file format used to carry meeting details.
Attackers exploit the implied trust around a scheduled appointment, then hide dangerous links or QR codes inside the invitation body.
John Gallagher, vice president at cyber hygiene provider Viakoo, said the attack benefits from default settings and from the fact that many users treat calendar entries as less suspicious than email.
A recent example used a Google Calendar invitation and a financial lure.
The message offered an alleged credit against a recent invoice and invited the target to a meeting to discuss it.
Because the invitation came from a Gmail account, domain-based filtering alone would not necessarily stop it.
Depending on the mail client, the event could still appear on the user’s calendar even if the email message itself was blocked.
The attack chain then moved from the calendar entry to a page hosted on Framer’s free hosting service.
The page prompted the victim to click a “View Here” button for the supposed credit note.
That button linked to a malicious file, and the download delivered an MSI installer if endpoint defenses did not stop it.
The MSI file carried more than a simple payload.
Sublime found configuration data that abused the legitimate ScreenConnect remote-access tool as command-and-control infrastructure.
Once installed, the tool could give attackers a way to issue commands to the infected system.
The defensive lesson is that declining a suspicious invitation is not necessarily safe.
Shane Barney, chief information security officer at Keeper Security, warned that clicking links, replying, accepting or even declining can confirm that an address is active.
Deleting the event directly and reporting it as spam where supported gives users a safer first response.
The larger control is to change how calendars treat unknown senders.
Gmail users can set Google Calendar to add invitations only from known senders or only after the user responds by email.
Classic Microsoft Outlook users can turn off automatic processing of meeting requests and automatic acceptance of meetings in the Mail and Calendar options.
Those changes do not remove the need for email and endpoint scanning, but they close the gap that makes the lure useful.
An unwanted calendar entry should be treated like an untrusted message: do not open embedded links, do not scan QR codes from the invite, and do not interact with the sender unless the meeting can be verified through a separate channel.




















