Invitation Emails Used to Steal Logins & Install RATs

Cofense · Medium sophistication
Last updated August 12, 2026

Cofense reports a sustained rise in real phishing campaigns disguised as party/event invitations that trick people into clicking links. The same invitation lure is being used both to steal usernames/passwords via fake login pages and to install legitimate-but-abused remote access tools that give attackers control of a computer. Some campaigns even change what victims receive based on whether they click from a desktop, Mac, or mobile device.

Key findings

  • Invitation-themed emails are being used in real campaigns to deliver both credential phishing pages and remote access malware.
  • Attackers spoof well-known invitation brands (Punchbowl, Greenvelope, Paperless Post, Evite) and rely on curiosity and emotional triggers to get clicks.
  • Some campaigns use device-detection so the same link can deliver different payloads to Windows, macOS, or mobile users from a single URL.
  • Polished design and branding can be indistinguishable from legitimate invitations, making appearance-based trust unreliable.
  • Abused legitimate remote tools (e.g., ConnectWise RAT/ScreenConnect, Datto RMM) can slip past defenses because they are commonly used by IT teams.

Who’s being targeted

  • Commonly targeted roles: All employees, Executives, Finance, HR, IT/Helpdesk.
  • Attack channels: email, website.
  • Impersonated: Punchbowl (spoofed invitation platform), Evite (spoofed invitation platform), Paperless Post (spoofed invitation platform).

Awareness takeaways

  • Treat unexpected invitations as risky, even if the branding looks perfect, and verify via a separate, known-good method.
  • Be cautious of emotionally charged subject lines designed to create urgency or curiosity (“don’t miss out”, “friends and family”).
  • Assume a single link can lead to different outcomes (credential theft on mobile, malware on desktop). Avoid clicking and report it.
  • Harden controls around remote access tools and don’t install unexpected “support” or “viewer” software prompted by an email.

Red flags to watch for

  • Subject line pressures a specific device use (e.g., “for desktop only”)
  • Unexpected invitation, possibly using a familiar name to reduce suspicion
  • Clicking leads to download behavior rather than simply viewing event details
  • Emotional language meant to override normal caution (e.g., “friends and family”)
  • Unexpected invitation from outside normal work context
  • Link click leads to software/tool delivery rather than a normal RSVP page
  • Same link behaves differently depending on device (unexpected redirects/downloads)
  • Mobile click prompts for credentials unrelated to a normal invitation flow
  • Invitation appears highly polished, making brand/visual checks unreliable
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You get a Punchbowl invite: “Birthday party – for desktop only.” Looks legit, nice graphics… and that’s the trap. Cofense is seeing real campaigns spoofing Punchbowl and Evite where that “View Invitation” link either steals your login or quietly installs a remote access tool like ConnectWise or Datto RMM. Here’s the aha: one shiny invite link can do device-detection, on your phone it shows a fake login page, on your Windows laptop it drops a RAT that gives someone full control of your machine. If you get an unexpected invite, especially “for desktop only” or “friends and family” at work, don’t click. Screenshot it and report it through our phishing reporting button.

Similar attacks

Phishing Installs “Legit” Remote Tools in 2 Stages

Phishing Installs “Legit” Remote Tools in 2 Stages

Cofense reports real phishing campaigns where attackers trick employees into installing legitimate remote access tools (like GoTo, Datto RMM, SimpleHelp, and ConnectWise). After the first tool is installed, it contacts a command-and-control server that directs it to download additional remote tools…

July 29, 2026
Fake Claude Max Promo Steals Google Logins

Fake Claude Max Promo Steals Google Logins

Researchers found a phishing campaign offering a “free” upgrade to Claude Max to trick people into signing in with Google. The page uses a convincing fake, draggable Google login window (“browser-in-the-browser”) to capture credentials, potentially giving criminals access to email, documents, and…

September 23, 2026
Fake ChatGPT Invoice Email Steals Logins

Fake ChatGPT Invoice Email Steals Logins

Attackers are sending fake ChatGPT billing emails that pressure people to “update payment” within 48 hours to avoid service interruption. The message links to a convincing look‑alike ChatGPT login page via a Google redirect, aiming to steal OpenAI credentials.

September 18, 2026
Fake ChatGPT Billing Email Steals OpenAI Logins

Fake ChatGPT Billing Email Steals OpenAI Logins

A phishing email posing as a ChatGPT billing notice pressures users to “update payment information” to avoid service interruption. The button routes through a Google redirect and lands on a fake OpenAI login page that captures usernames and passwords before sending victims to an error page.

September 17, 2026
Fake ChatGPT Invoice Steals Login Credentials

Fake ChatGPT Invoice Steals Login Credentials

Cofense observed a real phishing email that impersonates OpenAI/ChatGPT billing to trick users into “updating” payment details. The email uses the real ChatGPT logo, urgency (“48 hours”), and a prominent button to drive clicks to a lookalike ChatGPT login page. Any credentials entered are harvested…

September 17, 2026
Phishing Uses Google Links to Steal Microsoft Logins

Phishing Uses Google Links to Steal Microsoft Logins

Researchers reported an active, large-scale phishing campaign that starts with links hosted on legitimate Google services, then redirects victims to attacker-controlled sites. The final pages mimic Microsoft sign-in or “identity verification” flows to steal credentials/MFA codes or trick targets…

September 9, 2026