Calendar phishing attacks expanding across service providers · Blog · Sublime Security
ID: 258d9b0f-932b-5de6-8817-df3615008846
STIX ID: report--258d9b0f-932b-5de6-8817-df3615008846
Feed Name: Sublime Security Blog
Sublime’s Attack Spotlight documents a widespread calendar/ICS phishing campaign in which attackers embed callback-phishing payloads (phone numbers and malicious mailto/URLs) inside meeting invitations sent via legitimate services (Teams, Trafft, Zoho, Calendly, Demio). These attacks bypass many email defenses because payloads persist on calendars even when emails are blocked; the report provides multiple real-world examples, indicators (sender domains, reply-to addresses, freemail addresses, phone numbers), and detection/mitigation guidance (AI-powered calendar scanning, input validation by providers).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
