Threat Actors Exploit Calendar Subscriptions for Phishing and Malware Delivery
ID: f40d2429-0207-5a31-b2a0-823fccb9dc26
STIX ID: report--f40d2429-0207-5a31-b2a0-823fccb9dc26
Feed Name: Infosecurity Magazine (News)
Threat Score
BitSight research found threat actors leveraging calendar subscription infrastructure—frequently using expired or hijacked domains—to push malicious .ics events (URLs, attachments, JavaScript), enabling phishing, malware distribution, and emerging attacks; sinkholing uncovered 347 suspicious domains receiving ~4 million unique IPs/day and the report warns calendar subscriptions are an underappreciated security blind spot.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
