logo

Threat Actors Exploit Calendar Subscriptions for Phishing and Malware Delivery

ID: f40d2429-0207-5a31-b2a0-823fccb9dc26

STIX ID: report--f40d2429-0207-5a31-b2a0-823fccb9dc26

Feed Name: Infosecurity Magazine (News)

Threat Score
68/100

Date Published: 2025-11-28

Date Updated: 2026-04-22

...
...

BitSight research found threat actors leveraging calendar subscription infrastructure—frequently using expired or hijacked domains—to push malicious .ics events (URLs, attachments, JavaScript), enabling phishing, malware distribution, and emerging attacks; sinkholing uncovered 347 suspicious domains receiving ~4 million unique IPs/day and the report warns calendar subscriptions are an underappreciated security blind spot.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.