Invitation Emails Used to Steal Logins & Install RATs

Cofense · Medium sophistication
Last updated August 12, 2026

Cofense reports a sustained rise in real phishing campaigns disguised as party/event invitations that trick people into clicking links. The same invitation lure is being used both to steal usernames/passwords via fake login pages and to install legitimate-but-abused remote access tools that give attackers control of a computer. Some campaigns even change what victims receive based on whether they click from a desktop, Mac, or mobile device.

Key findings

  • Invitation-themed emails are being used in real campaigns to deliver both credential phishing pages and remote access malware.
  • Attackers spoof well-known invitation brands (Punchbowl, Greenvelope, Paperless Post, Evite) and rely on curiosity and emotional triggers to get clicks.
  • Some campaigns use device-detection so the same link can deliver different payloads to Windows, macOS, or mobile users from a single URL.
  • Polished design and branding can be indistinguishable from legitimate invitations, making appearance-based trust unreliable.
  • Abused legitimate remote tools (e.g., ConnectWise RAT/ScreenConnect, Datto RMM) can slip past defenses because they are commonly used by IT teams.

Who’s being targeted

  • Commonly targeted roles: All employees, Executives, Finance, HR, IT/Helpdesk.
  • Attack channels: email, website.
  • Impersonated: Punchbowl (spoofed invitation platform), Evite (spoofed invitation platform), Paperless Post (spoofed invitation platform).

Awareness takeaways

  • Treat unexpected invitations as risky, even if the branding looks perfect, and verify via a separate, known-good method.
  • Be cautious of emotionally charged subject lines designed to create urgency or curiosity (“don’t miss out”, “friends and family”).
  • Assume a single link can lead to different outcomes (credential theft on mobile, malware on desktop). Avoid clicking and report it.
  • Harden controls around remote access tools and don’t install unexpected “support” or “viewer” software prompted by an email.

Red flags to watch for

  • Subject line pressures a specific device use (e.g., “for desktop only”)
  • Unexpected invitation, possibly using a familiar name to reduce suspicion
  • Clicking leads to download behavior rather than simply viewing event details
  • Emotional language meant to override normal caution (e.g., “friends and family”)
  • Unexpected invitation from outside normal work context
  • Link click leads to software/tool delivery rather than a normal RSVP page
  • Same link behaves differently depending on device (unexpected redirects/downloads)
  • Mobile click prompts for credentials unrelated to a normal invitation flow
  • Invitation appears highly polished, making brand/visual checks unreliable
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You get a Punchbowl invite: “Birthday party – for desktop only.” Looks legit, nice graphics… and that’s the trap. Cofense is seeing real campaigns spoofing Punchbowl and Evite where that “View Invitation” link either steals your login or quietly installs a remote access tool like ConnectWise or Datto RMM. Here’s the aha: one shiny invite link can do device-detection, on your phone it shows a fake login page, on your Windows laptop it drops a RAT that gives someone full control of your machine. If you get an unexpected invite, especially “for desktop only” or “friends and family” at work, don’t click. Screenshot it and report it through our phishing reporting button.

Similar attacks

Phishing Installs “Legit” Remote Tools in 2 Stages

Phishing Installs “Legit” Remote Tools in 2 Stages

Cofense reports real phishing campaigns where attackers trick employees into installing legitimate remote access tools (like GoTo, Datto RMM, SimpleHelp, and ConnectWise). After the first tool is installed, it contacts a command-and-control server that directs it to download additional remote tools…

July 29, 2026
Fake ChatGPT Billing Emails Steal Card Details

Fake ChatGPT Billing Emails Steal Card Details

Check Point reports that scammers are now impersonating ChatGPT/OpenAI in phishing campaigns, reflecting how mainstream the service has become. One documented example used a fake “ChatGPT Plus payment failure” notice that sent victims to a fraudulent payment page designed to capture full credit…

July 28, 2026
Fake ChatGPT Billing Emails Steal Card Details

Fake ChatGPT Billing Emails Steal Card Details

Check Point reports that OpenAI’s ChatGPT became a top-10 most impersonated brand in Q2 2026 phishing. One observed example used a fake “ChatGPT Plus payment failed” billing email to drive victims to a credit-card theft page. The report also notes other brand-impersonation scams using cloned stores…

July 24, 2026
Fake Google Ads “Sync” Alert Steals Credentials

Fake Google Ads “Sync” Alert Steals Credentials

Cofense observed a real phishing campaign impersonating Google Ads Sync Accounts (MMC) with a fake “maintenance/system upgrade” notice. The email pressures recipients to click “Complete Sync Account,” sending them through lookalike sites and a fake Google sign-in pop-up that captures credentials.…

July 21, 2026
Fake Voicemail Alert Steals Google Passwords

Fake Voicemail Alert Steals Google Passwords

A real phishing campaign is tricking employees with a “missed voicemail” message that claims they have a new audio message. Clicking “Play Audio” sends victims through multiple trusted-looking redirects and ends on a fake Google sign-in page that captures Google Workspace credentials, potentially…

August 12, 2026
Fake WhatsApp/Instagram Sites Abuse HTTPS Padlock

Fake WhatsApp/Instagram Sites Abuse HTTPS Padlock

Researchers reported a phishing setup that clones WhatsApp and Instagram login pages and uses valid HTTPS (TLS) certificates to look legitimate. Victims are lured via WhatsApp messages about “verification,” “pending payments,” or “customer support,” then sent to typosquatted lookalike domains to…

August 11, 2026