logo

The Payload Was a Phone Number: How a Google Calendar Invite Weaponized Vishing

ID: 8bf4bcdb-108d-5d4e-adb7-bc679d4427a9

STIX ID: report--8bf4bcdb-108d-5d4e-adb7-bc679d4427a9

Feed Name: IRONSCALES

Threat Score
65/100

Date Published: 2026-04-03

Date Updated: 2026-04-28

Author: [email protected] (Audian Paxson)

...
...

A threat actor registered scoolsd.com on 2026-03-17 and used a Google Workspace account to send a calendar invite impersonating a billing notice for “CoreDefense Plus” that contained a toll-free callback number ((808)-321-8085) to phone-social-engineer the recipient; there were no malicious links or executable payloads, DKIM passed, SPF was absent, and the only technical IOCs were the domain, sender email, phone number, and an ICS file hash.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.