Fake calendar invites can infect your system, and they’re surging – how to protect yourself

A report from cybersecurity firm Sublime highlights a sharp rise in calendar-based malware attacks, known as ICS phishing, according to ZDNET. Such attacks rose 282% in June over the prior month, 338% in July, and 1,216% in August. Sublime projects a 2,852% increase for September over August.
An ICS file, part of the iCalendar standard, contains the details of a meeting or appointment invitation. In programs such as Microsoft Outlook, Gmail and Apple Mail, an ICS file sent by email can be added to a calendar automatically before the recipient accepts or declines it. Because the invite reaches both inbox and calendar, and most email programs are designed to block attacks in the inbox but not the calendar, an event can remain even if the email itself is caught by security software.
Sublime said most of these attacks use Google's platform, Gmail via Google Calendar, with many also sent through Microsoft infrastructure. One attack it highlighted used a Google Calendar invite to deliver a link to a malicious remote monitoring and management payload, with a financial lure about an alleged credit against a recent invoice. Clicking the link led to a page hosted by Framer, then a download of an MSI file that Sublime said includes configuration exploiting the legitimate ScreenConnect tool as a command-and-control server.
John Gallagher, VP at Viakoo, told ZDNET the attacks rely on implied trust in the systems and the invitation, and that links or QR codes inside an invite can compromise a system, while even rejecting an invite can tell an attacker the email address is valid. Shane Barney, Chief Information Security Officer at Keeper Security, said people should not click links, RSVP, or click Decline, and should delete the event and report it as spam. He suggested disabling automatic addition of invitations from unknown senders.
Sublime threat detection engineer Mark Morris advised checking the sender's address and domain, judging links in invites as in email, watching for urgency, never authenticating an account from a calendar invite, and reporting and deleting such messages.
Based on reporting from the original publisher. Visit the source for full context and later updates.
Publisher excerpt
These invites sneak past your security software to embed themselves in your calendar. But you can thwart them before they do any damage.