Attackers are abusing legitimate Microsoft 365 collaboration features to deliver phishing lures that look like routine internal activity, according to Fortra researchers. The campaign uses attacker-controlled or compromised Microsoft 365 Groups to add victims into spaces named like IT Support, HR Updates, or All Company, then pushes follow-on lures through group mailboxes, shared files, welcome messages, and calendar invitations. Messages are framed around urgent business themes such as payroll, contracts, supplier requests, and mandatory training to blend into normal workplace workflows and lower suspicion.
A key tactic is CalPhishing, in which malicious .ics calendar events are used to place phishing items directly on a victim’s calendar and generate repeated reminders over time. Researchers said the repeated exposure across email, groups, files, and calendar surfaces can make the lure appear to be a legitimate unfinished task, while the end goals include credential theft, token capture, malware delivery, data exposure, and further social engineering. Because the activity is distributed across trusted Microsoft infrastructure, investigations are more complex; defenders were advised to review the full chain of group creation, membership changes, shared content, and lingering calendar entries, and to consider blocking the sender domain groups.outlook.com where appropriate.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
1 event from the most recent confirmed update back to the earliest known activity.
Fortra reported a phishing campaign that abuses legitimate Microsoft 365 collaboration features, including Outlook Groups, shared files, group mailboxes, and calendar invitations, to make lures appear like routine workplace activity. The campaign includes CalPhishing techniques using .ics calendar events and repeated reminders to sustain exposure and drive credential theft, token theft, malware delivery, data exposure, or further social engineering.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.