logo

Impersonated Evite and Punchbowl invitations used for credential phishing and malware distribution · Blog · Sublime Security

ID: 002d05c5-c617-52c2-9c53-ffb9966a91b9

STIX ID: report--002d05c5-c617-52c2-9c53-ffb9966a91b9

Feed Name: Sublime Security Blog

Threat Score
65/100

Date Published: 2025-10-22

Date Updated: 2026-05-01

...
...

Sublime’s Attack Spotlight details active invitation-themed email campaigns impersonating brands like Evite and Punchbowl that deliver credential-phishing pages and malicious RMM payloads (e.g., MSI/EXE installers). The report includes observed hosting domains (pages.dev, r2.dev, storage.googleapis.com, workers.dev, restoreds.de), example malicious filenames, variant behaviors (Cloudflare Turnstile redirects, fake multi-provider login flows, auto-downloaded RMM tools), and detection signals used to block them.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.