logo

The Webinar Invite That Came With an Apple Wallet Pass and a Three-Hop Redirect Chain

ID: 836a5666-a05d-5077-8d5d-1125fda8cbea

STIX ID: report--836a5666-a05d-5077-8d5d-1125fda8cbea

Feed Name: IRONSCALES

Threat Score
70/100

Date Published: 2026-05-19

Date Updated: 2026-05-19

Author: [email protected] (Audian Paxson)

...
...

A high-risk phishing campaign spoofed a Google Calendar webinar invitation and used a structurally clean .ics file and a .pkpass Apple Wallet attachment to deliver redirecting short links and a webServiceURL with tracking tokens; the message passed SPF/DKIM/DMARC via Google infrastructure, triggered behavioral detections, quarantined multiple mailboxes, and provides several IoCs and MITRE mappings for detection and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.