logo

ICS phishing: Stopping a surge of malicious calendar invites · Blog · Sublime Security

ID: 9eb43c7a-2141-5f6b-8f68-46af1178d111

STIX ID: report--9eb43c7a-2141-5f6b-8f68-46af1178d111

Feed Name: Sublime Security Blog

Threat Score
60/100

Date Published: 2025-12-18

Date Updated: 2026-05-01

...
...

This Attack Spotlight details a surge in "ICS phishing" attacks that abuse calendar invitation behavior in Google Workspace and Microsoft 365 to deliver phishing payloads and leave malicious events on users' calendars even when emails are blocked. The report presents examples (FreeConferenceCall abuse, QR-code leading to credential phishing, attached HTML phishing kits), detection signals (malicious QR links, brand impersonation, suspicious HTML/JS artifacts), and mitigation advice including Google Workspace settings and Sublime's automated removal of malicious calendar events.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.