Malicious Calendar Invites Surge With Malware Links

ZDNet Security · Medium sophistication
Last updated September 18, 2026

Attackers are sending fake calendar meeting invites that can be automatically added to a victim’s calendar, even if the email is blocked. A documented example used a Google Calendar invite with a financial “invoice credit” lure to drive victims to a hosted webpage and download a malicious installer. The risk is that people trust calendar entries more than emails and may click links or QR codes inside the invite.

Key findings

  • Calendar-based phishing/malware attacks (ICS invites) are rising sharply, with Sublime reporting large month-over-month increases.
  • Many email/calendar tools can auto-add invites to calendars before a user accepts/declines, increasing exposure.
  • A real example used a financial lure (“credit against a recent invoice”) to drive the target to a hosted page and download a malicious MSI.
  • Even declining/RSVP’ing can help attackers confirm the email address is active.
  • Attackers abused trusted infrastructure (Google Calendar/Gmail and Microsoft infrastructure) and free hosting (Framer) to evade detection.
  • The downloaded MSI abused a legitimate remote access tool (ScreenConnect) to provide command-and-control capabilities.

Who’s being targeted

  • Commonly targeted roles: All employees, Finance/AP/AR teams, Executive assistants and heavy calendar users, IT/Helpdesk (to support reporting and calendar-setting changes).
  • Affected industries: Any organization using Microsoft Outlook, Gmail/Google Calendar, or Apple Mail, Finance and Accounts Payable/Receivable teams (invoice/credit lures).
  • Attack channels: email.
  • Impersonated: A billing or accounts department (invoice/credit issuer).

Awareness takeaways

  • Treat calendar invites like emails: don’t click links or QR codes in invites you weren’t expecting; delete/report instead.
  • Do not RSVP/Decline suspicious invites, delete the calendar event directly to avoid confirming your address is active.
  • Reduce risk by changing calendar settings so invites from unknown senders are not automatically added to calendars.
  • Be skeptical of urgency or financial pressure in meeting invites (e.g., invoice credits) and verify through trusted channels.

Red flags to watch for

  • Unexpected invoice/credit notice pushing you to click a link
  • Invite appears in calendar even before you accepted it
  • Hosted on a generic/free site and uses a generic button like “View Here” to download a file
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You block a sketchy email… but the meeting invite from it still lands on your calendar. Attackers are abusing Google Calendar-style invites with a fake 'credit against a recent invoice' meeting. Inside is a link to a Framer-hosted page and a big 'View Here' button that drops a malicious MSI using ScreenConnect remote access. Three red flags: you weren’t expecting any invoice credit, the invite appeared on your calendar before you accepted, and it pushes you to click a generic link or QR code to download a file. If a calendar invite feels off, don’t click, don’t RSVP, just delete the event from your calendar and, if it’s work-related, report it.

Similar attacks

Job Offer & Doc-Link Phishing Drive Real Breaches

Job Offer & Doc-Link Phishing Drive Real Breaches

This weekly threat bulletin describes real incidents where attackers used human manipulation to break in, including social engineering at Levi Strauss and a Microsoft 365 credential-theft phish at defense supplier IEH. It also highlights a Lazarus-linked campaign using fake job offers and…

August 17, 2026
Fake AI Trading Bot Steals Crypto Wallet Passwords

Fake AI Trading Bot Steals Crypto Wallet Passwords

Researchers observed real campaigns where a fake “AI crypto trading agent” website tricked victims into downloading malware that silently replaces browser wallet extensions and steals the wallet password when it’s typed. The same reporting also describes invoice emails using QR codes to push…

September 17, 2026
Fake Recruiters & Cloud Email Fuel New Phishing

Fake Recruiters & Cloud Email Fuel New Phishing

This roundup describes real-world social engineering where attackers impersonate recruiters on LinkedIn and lure developers into running “coding tests” that install malware. It also outlines active phishing campaigns that abuse trusted cloud services (Google, AWS, Azure, Cloudflare) to send…

September 2, 2026
Lazarus Lures Staff With Fake Jobs to Drop Malware

Lazarus Lures Staff With Fake Jobs to Drop Malware

Researchers tied North Korea’s Lazarus Group to a real-world campaign that approaches professionals with convincing fake recruiter outreach and job offers. Victims are tricked into opening a malicious PDF or installing a fake PDF viewer from lookalike websites, which then installs backdoors and can…

August 12, 2026
Fake Job Offers Spread Lazarus Zero-Day Attack

Fake Job Offers Spread Lazarus Zero-Day Attack

Researchers describe a real, ongoing Lazarus-linked campaign where targets are lured with attractive job offers and tricked into downloading a PDF viewer and “job description” documents. Opening the files installs backdoors and, in at least one wave, attackers used a Windows zero-day to gain deep…

August 11, 2026
Fake Claude & Perplexity Lures Push Malware

Fake Claude & Perplexity Lures Push Malware

Sophos reports real incidents where attackers impersonated well-known AI brands (especially Claude) to trick people into installing malware. The lures included polished fake installer pages that instruct victims to copy/paste commands, and browser extensions that look legitimate via high ratings…

August 21, 2026