The Payload Was a Phone Number: How a Google Calendar Invite Weaponized Vishing
ID: 8bf4bcdb-108d-5d4e-adb7-bc679d4427a9
STIX ID: report--8bf4bcdb-108d-5d4e-adb7-bc679d4427a9
Feed Name: IRONSCALES
Threat Score
A threat actor registered scoolsd.com on 2026-03-17 and used a Google Workspace account to send a calendar invite impersonating a billing notice for “CoreDefense Plus” that contained a toll-free callback number ((808)-321-8085) to phone-social-engineer the recipient; there were no malicious links or executable payloads, DKIM passed, SPF was absent, and the only technical IOCs were the domain, sender email, phone number, and an ICS file hash.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
