Microsoft Bookings as a Weapon: When DMARC Says Trust Me and ARC Quietly Disagrees
ID: a35a33bc-4d8d-5652-9634-48b2f80af47f
STIX ID: report--a35a33bc-4d8d-5652-9634-48b2f80af47f
Feed Name: IRONSCALES
Attackers weaponized Microsoft Bookings to send realistic appointment confirmations to eight employees at a U.S. government contractor; messages passed SPF/DKIM/DMARC but exhibited an ARC chain failure, a divergent Reply-To address, inline base64 imagery instead of CDN-hosted assets, and included a booking.ics calendar attachment—behavioral anomalies that triggered mitigation before recipients interacted. The report highlights that authentication pass ≠ trust, details IOC artifacts (sender domain, sender email, Reply-To, ARC-Seal failure, ICS file hash, inline image), and recommends prioritizing ARC integrity checks, Reply-To divergence detection, inline image anomalies, sender-relationship analysis, and cautious handling of ICS attachments.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
