Attackers are abusing Outlook calendar invites in an active CalPhishing campaign to hijack Microsoft 365 accounts by delivering malicious .ics files that automatically place tentative meetings on victims’ calendars. Researchers at Fortra Intelligence and Research Experts (FIRE) said the invites impersonate urgent administrative notices such as Microsoft 365 domain renewal warnings and digital-signature invoice requests, with manipulated SUMMARY, LOCATION, and DESCRIPTION fields directing users to fake Microsoft 365, GoDaddy, or DocuSign pages. Because the calendar entry can remain visible even if the original email is deleted or sent to junk, the lure continues to generate trusted reminders and increases the chance of user interaction.
The campaign uses HTML landing pages and redirect chains through Cloudflare to reduce detection, and researchers believe the operators are likely using the EvilTokens phishing kit sold on Telegram to automate the attacks. FIRE warned that the activity appears to incorporate ConsentFix-style device code phishing to steal session tokens rather than just passwords, allowing attackers to bypass MFA and maintain access to compromised accounts. The combination of trusted calendar workflows, persistent invites, and likely AI-assisted automation makes the technique a significant threat to enterprise account security and data privacy.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
On publication of the research, FIRE disclosed technical details of the CalPhishing technique, warning that calendar entries can persist even if the original email is deleted or sent to junk. The researchers also assessed that the attackers were likely using the EvilTokens phishing kit sold on Telegram to automate the campaign.
In the campaign, attackers modified iCalendar fields to impersonate urgent notices such as Microsoft 365 domain renewal alerts and invoice or signature requests, directing victims to fake GoDaddy, Microsoft 365, or DocuSign pages. Researchers said the operation used HTML lures, Cloudflare redirect chains, and ConsentFix-style device code phishing to steal session tokens and bypass MFA.
Fortra Intelligence and Research Experts (FIRE) reported that an active phishing campaign abusing Outlook calendar invites has been underway since early 2026. The operation targets Microsoft 365 users by sending emails with malicious .ics files that create tentative meetings directly on victims’ calendars.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcehackread.com
Open sourcesublime.security
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.