CalPhishing Scam Uses EvilTokens Kit, Outlook Invites to Steal M365 Sessions
ID: 712382d1-ebf8-5a66-9fcc-4e6dd7df0a2e
STIX ID: report--712382d1-ebf8-5a66-9fcc-4e6dd7df0a2e
Feed Name: HackRead
Threat Score
**CalPhishing campaign:** Cybercriminals send malicious .ics calendar invites that auto-create meetings and present HTML landing pages (via Cloudflare redirects) mimicking Microsoft/DocuSign pages; attackers use ConsentFix/device-code phishing and the EvilTokens kit to steal session tokens (bypassing MFA), with invites persisting on calendars and AI automation used to scale the attacks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
