logo

Microsoft Bookings as a Weapon: When DMARC Says Trust Me and ARC Quietly Disagrees

ID: a35a33bc-4d8d-5652-9634-48b2f80af47f

STIX ID: report--a35a33bc-4d8d-5652-9634-48b2f80af47f

Feed Name: IRONSCALES

Threat Score
70/100

Date Published: 2026-04-03

Date Updated: 2026-04-28

Author: [email protected] (Audian Paxson)

...
...

Attackers weaponized Microsoft Bookings to send realistic appointment confirmations to eight employees at a U.S. government contractor; messages passed SPF/DKIM/DMARC but exhibited an ARC chain failure, a divergent Reply-To address, inline base64 imagery instead of CDN-hosted assets, and included a booking.ics calendar attachment—behavioral anomalies that triggered mitigation before recipients interacted. The report highlights that authentication pass ≠ trust, details IOC artifacts (sender domain, sender email, Reply-To, ARC-Seal failure, ICS file hash, inline image), and recommends prioritizing ARC integrity checks, Reply-To divergence detection, inline image anomalies, sender-relationship analysis, and cautious handling of ICS attachments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.