ICS phishing: Stopping a surge of malicious calendar invites · Blog · Sublime Security
ID: 9eb43c7a-2141-5f6b-8f68-46af1178d111
STIX ID: report--9eb43c7a-2141-5f6b-8f68-46af1178d111
Feed Name: Sublime Security Blog
This Attack Spotlight details a surge in "ICS phishing" attacks that abuse calendar invitation behavior in Google Workspace and Microsoft 365 to deliver phishing payloads and leave malicious events on users' calendars even when emails are blocked. The report presents examples (FreeConferenceCall abuse, QR-code leading to credential phishing, attached HTML phishing kits), detection signals (malicious QR links, brand impersonation, suspicious HTML/JS artifacts), and mitigation advice including Google Workspace settings and Sublime's automated removal of malicious calendar events.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
