Calendar-invitation phishing, or ICS phishing, is surging by abusing .ics invitations and the automatic calendar-processing behavior of Gmail, Outlook, and Apple Mail. Sublime Security reported month-over-month growth of 282% in June, 338% in July, and 1,216% in August, projecting a 2,852% increase for September. Malicious events can appear on a recipient’s calendar before they accept or decline the invitation, lending fraudulent messages credibility through trusted Google and Microsoft infrastructure.
In one observed campaign, attackers sent a Google Calendar invitation posing as a credit for a recent invoice. The lure directed targets to a Framer-hosted site that delivered a malicious MSI installer configured to misuse the legitimate ScreenConnect remote-access tool for command-and-control. Organizations should disable automatic addition of invitations from unknown senders and instruct users not to open links, scan QR codes, RSVP, or decline unsolicited calendar events; suspicious invitations should be reported and deleted.

Get the infrastructure and lures behind it.
4 events from the most recent confirmed update back to the earliest known activity.
A campaign sent a Gmail-originated Google Calendar invitation using a purported invoice-credit lure. Its link led to a Framer-hosted page that delivered a malicious MSI configured to abuse the legitimate ScreenConnect remote-access tool for command-and-control.
Sublime Security reported that calendar-based malware attacks increased 1,216% in August compared with July.
Sublime Security reported a 338% month-over-month increase in calendar-based malware attacks in July.
Sublime Security reported that calendar-based malware attacks using ICS phishing increased 282% in June compared with the preceding month.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.