AI News Feed
Market watch
Cybersecurity

Fake Calendar Invites Fuel Sharp Rise in Malware Attacks

Fake calendar invitations are being used to deliver malware at sharply higher rates, according to cybersecurity firm Sublime, with attacks up 1,216% in August and projected to rise 2,852% in September. The scams exploit automatic calendar settings in Outlook, Gmail, and Apple Mail, and experts urge users not to click, RSVP, or decline.

The attacks use a technique Sublime calls ICS phishing. An ICS file is part of the iCalendar standard and contains details for a meeting or appointment invitation. In programs including Microsoft Outlook, Gmail, and Apple Mail, an ICS file sent by email can be added automatically to a user’s calendar before the user decides whether to accept or decline it.

The scams are effective for several reasons, according to ZDNET. Meeting invitations go to both the inbox and the calendar, exposing users in two places. Most email programs are designed to prevent attacks in the inbox, but not in the calendar. Even if security software catches the email itself, the event is often added to the calendar and remains there. Many attacks are deployed through Google’s platform, meaning Gmail via Google Calendar, and many are also sent through Microsoft’s infrastructure; both are trusted services that can evade detection. The attacks also typically exploit free services, so scammers face no cost.

“What makes these attacks successful is the implied trust — both systems involved and of the invitation itself,” John Gallagher, vice president at cyber hygiene provider Viakoo, told ZDNET. “The attacker is assuming default settings are in place, and that calendar invites are not as suspect as email phishing is. The danger is with what is inside the invite; links or QR codes can compromise the victim’s system, and even rejecting the invite can send the attacker information on the email address being valid.”

One recent attack highlighted by Sublime used a Google Calendar invite to deliver a link to a malicious remote monitoring and management payload, ZDNET reported. The email used a known financial lure: it tempted users with an alleged credit against a recent invoice and invited them to a meeting to discuss it. The meeting invite came from a Gmail account, so it would not have been blocked based on the domain. Depending on the user’s email software, the invite would likely have passed through security scans and been added automatically to the inbox. Even if the email had been blocked by security defenses, it would still have ended up on the target’s calendar.

If the intended victim clicked the link in the email or calendar entry, ZDNET reported, they would be taken to a page hosted by Framer, which offers a free hosting plan. There, the person is prompted to click a “View Here” button to download the alleged credit note, which actually links to a malicious file. Unless the download is blocked by security software, an MSI installation file is downloaded. The MSI file contains malware and configuration information that exploits the legitimate remote access tool ScreenConnect to act as a Command and Control server, which attackers can use to exploit infected systems and issue commands.

Shane Barney, chief information security officer at cybersecurity software provider Keeper Security, told ZDNET that individuals should never click links, RSVP, or even click decline, because doing so confirms the email is active. He said users should delete the event directly and report it as spam if their email provider has that feature. Users can also tighten calendar settings by disabling the option that automatically adds invitations from unknown senders, he said.

Depending on the email program, users can typically turn off the setting that automatically adds a meeting invitation to their calendar, according to ZDNET. The report says Gmail users can find the relevant option in Google Calendar under Event Settings, where the menu for “Add invitations to my calendar” is located.

Editor's Summary

Fake calendar invitations are being weaponized to deliver malware, with Sublime reporting sharp month-over-month increases through August and a projected 2,852% rise in September. Attackers exploit automatic calendar settings in widely used email and calendar services, where invites can bypass inbox defenses. Security experts advise deleting suspicious events without clicking, RSVPing, or declining, and disabling automatic additions from unknown senders.