Lance Whitney/ZDNETZDNET’s key takeaways
- Fake meeting invites can infect your system with malware.
- Many email programs may automatically add invites to your calendar.
- Don’t respond to the email or invite. Instead, report them and delete them.
Have you ever received a calendar invite via email that turned out to be fake and even malicious? I’ve gotten these in Microsoft Outlook. Many email programs automatically add an invite to your calendar before you can even accept or decline it. That means you may not be aware that the event information is now in your calendar, waiting for you to access it.
A new report from cybersecurity firm Sublime highlights a dramatic rise in these calendar-based malware attacks. Over the past few months, such attacks rose by 282% in June over the prior month, by 338% in July, and by a whopping 1,216% in August. For September, the firm projects a 2,852% increase over August.
Also: Inside Google’s faster Chrome patch strategy to block AI attacks on your browser
These scams are gaining in popularity for a couple of reasons. They’re relatively easy to pull off. And they take advantage of a default setting for calendar invites in many email programs.
To pull off these attacks, scammers use a technique that Sublime calls ICS phishing. Part of the iCalendar standard, an ICS file contains the details for a meeting or appointment invitation. In programs such as Microsoft Outlook, Gmail, and Apple Mail, an ICS file sent via email can automatically be added to your calendar before you even decide to accept or decline the invite.
Why are these scams so effective?
These types of scams prove successful for several reasons.
- The meeting invites are sent to both your inbox and your calendar, exposing you in two places.
- Most email programs are designed to prevent attacks in your inbox, but not your calendar. Even if the email itself is caught by security software, the event is added to your calendar and often remains there.
- Most of these attacks are deployed using Google’s platform, meaning Gmail via Google Calendar. Many are also sent via Microsoft’s infrastructure. Both are trusted services that can evade detection.
- These attacks typically exploit free services, so there’s no cost to the scammers.
Also: Windows 11 out-of-band update fixes audio glitch and other bugs – grab it now
“What makes these attacks successful is the implied trust — both systems involved and of the invitation itself,” John Gallagher, VP at cyber hygiene provider Viakoo, told ZDNET. “The attacker is assuming default settings are in place, and that calendar invites are not as suspect as email phishing is. The danger is with what is inside the invite; links or QR codes can compromise the victim’s system, and even rejecting the invite can send the attacker information on the email address being valid.”
One recent attack highlighted by Sublime used a Google Calendar invite to deliver a link to a malicious remote monitoring and management (RMM) payload. The email itself employed a known financial lure tactic. In this case, the message tempted users with an alleged credit against a recent invoice, inviting them to a meeting to discuss the matter.
The meeting invite came from a Gmail account, which means it would not have been blocked, at least not based on the domain. Depending on the user’s email software, the invite would also likely have passed through any security scan, so that it would automatically be added to the person’s inbox. Even if the email were to be blocked by security defenses, it would still end up on the target’s calendar.
Also: Mobile phishing is a bigger threat than email now – how to stay protected
Should the intended victim click on the link in the email or calendar entry, they’d be taken to a page hosted by Framer, which offers a free hosting plan. From there, the person is prompted to click a View Here button to download the alleged credit note, which actually links to a malicious file. Unless the download is blocked by security software, the resulting MSI installation file is downloaded.
Beyond containing malware, the MSI file includes configuration information that exploits the legitimate remote access ScreenConnect tool to act as a Command and Control server. The attackers can then use the C2 server to exploit infected systems and issue commands to them.
The best defense against these attacks
How can you protect yourself and your company from these types of attacks?
“Individuals should never click on links, RSVP, or even click Decline because it confirms your email is active,” Shane Barney, Chief Information Security Officer at cybersecurity software Keeper Security, told ZDNET. “Instead, you should delete the event directly and report it as spam if your email provider has the feature. You can also tighten your calendar settings by disabling the setting that automatically adds invitations to your calendar from unknown senders.”
Depending on your email program, you can typically turn off the setting that automatically adds a meeting invite to your calendar. Here’s how.
For Gmail, go to Google Calendar. Click the Gear icon and select Settings. Under General, select Event Settings. Click the drop-down menu for “Add invitations to my calendar” and change the setting to “Only if the sender is known” or even better to “When I respond to the invitation in email.”
For classic Microsoft Outlook, go to the File menu, select Options, and then click Mail. Scroll to the bottom of the Mail screen to the Tracking section. Uncheck the box for “Automatically process meeting requests and responses to meeting requests and polls.” Next, go to the Calendar screen in Outlook Options. Scroll to the bottom of the “Automatic accept or decline” section. Click the button for Auto Accept/Decline and uncheck the box for “Automatically accept meeting requests and remove canceled meetings.” Click OK and OK again.
Also: Best VPN services: Expert tested and recommended
Mark Morris, threat detection engineer at Sublime Security, also offers a few tips for protecting yourself.
- Scrutinize the sender’s email address and domain name, not just the display name. Look for any inconsistencies.
- Judge the link in the invite the same way you would judge it in the email. If it looks off, avoid clicking on it and simply delete the event from your calendar.
- Beware if the email or invite urges you to act immediately. Most benign meeting invites aren’t going to prompt you to do something ASAP, financial or otherwise. Attackers use these kinds of threats to pressure people and lure them in.
- Never authenticate your account from a calendar invite. No legitimate invite will ask you to confirm a password or log in to an account.
- Never respond to the email or meeting invite. Instead, report them as phishing attempts and delete them. Attackers often look for live inboxes. Even if you decline the invite, they’ll know your account is active.
Lance Whitney is a technology journalist with an IT background. He's written for TechRepublic, PCMag, Macworld, and Time, among others, He also teaches classes in AI, cybersecurity, and social media. See full bio








English (US) ·