logo

Phishing Attack Weaponizes Calendar Invites to Steal Login Credentials

ID: e1a6ec80-c426-56c8-a659-4a921057e6a0

STIX ID: report--e1a6ec80-c426-56c8-a659-4a921057e6a0

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-05-06

Date Updated: 2026-05-06

Author: Mayura Kathir

...
...

A large-scale phishing campaign is abusing event-themed invitations that route victims through CAPTCHA checks and then either collect credentials and OTPs via fake sign-in flows or silently deliver legitimate remote monitoring and management (RMM) software (e.g., ScreenConnect, ITarian, Datto RMM, ConnectWise, LogMeIn Rescue) to gain persistent access. The report describes a reusable phish kit and provides concrete IOCs and request patterns (for example /blocked.html, /favicon.ico, /Image/*.png and POST endpoints like /processmail.php), and recommends tuning detections, monitoring for unauthorized RMM installs, and using dynamic analysis to safely investigate suspicious invitations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.