logo

CalPhishing Scam Uses EvilTokens Kit, Outlook Invites to Steal M365 Sessions

ID: 712382d1-ebf8-5a66-9fcc-4e6dd7df0a2e

STIX ID: report--712382d1-ebf8-5a66-9fcc-4e6dd7df0a2e

Feed Name: HackRead

Threat Score
70/100

Date Published: 2026-05-15

Date Updated: 2026-05-15

Author: Deeba Ahmed

...
...

**CalPhishing campaign:** Cybercriminals send malicious .ics calendar invites that auto-create meetings and present HTML landing pages (via Cloudflare redirects) mimicking Microsoft/DocuSign pages; attackers use ConsentFix/device-code phishing and the EvilTokens kit to steal session tokens (bypassing MFA), with invites persisting on calendars and AI automation used to scale the attacks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.