Friday, September 11, 2026

Phishing Attack Weaponizes Calendar Invites to Steal Login Credentials

A new large-scale phishing campaign is abusing fake event invitations to compromise U.S. organizations, combining credential theft, OTP interception, and the deployment of remote monitoring and management (RMM) tools in a single operation.

The campaign stands out because it blends familiar user workflows with legitimate-looking infrastructure, making it harder for security teams to spot and contain early.

The attack typically begins when a victim clicks a link in an email that appears to be a corporate or social event invitation.

Instead of going straight to a login form, the user is first sent through a CAPTCHA page, often presented as a Cloudflare check, which helps filter out automated scanners and makes the flow feel routine.

After passing the CAPTCHA, the victim lands on an event-themed page that claims they have received an invitation and must sign in or download details to proceed.

ANY.RUN researchers found that the campaign uses a repeatable phishing framework to create event-themed lure pages at scale.

From this point, the chain can move in two directions: towards credential theft and OTP interception, or towards the installation of legitimate RMM software such as ScreenConnect, ITarian, Datto RMM, ConnectWise, or LogMeIn Rescue.

Phishing Attack Weaponizes Calendar

When the page is configured for credential theft, users are prompted to choose a mail or identity provider and then enter their login details on a fake sign-in form.

For non-Google services, victims see a generic login window that asks for email and password; after the first attempt, the page always shows an “Incorrect Password” message to coax a second entry, giving attackers two copies of the credentials in case of typos.

Once the victim submits credentials, the page sends a POST request to attacker-controlled endpoints such as /processmail.php to capture the email and password, followed by a second form that asks for a one-time password (OTP).

The OTP is then exfiltrated through another POST request (for example, to /process.php), allowing attackers to bypass multi-factor authentication and access corporate mailboxes or other services with full session control.

In the RMM delivery path, the fake invitation page pushes a download that appears to be related to the event but actually installs a legitimate remote management tool.

In some observed cases, the download starts automatically as soon as the page loads, while in others it is triggered by a “Download invitation” button that still initiates the file transfer without extra confirmation.

Example message to sign in an event (Source : ANY.RUN).

Because tools like ScreenConnect, ITarian, Datto RMM, ConnectWise, and LogMeIn Rescue are widely used by IT teams, their presence on endpoints may not immediately raise alarms.

This lets attackers establish persistent remote access that blends into normal admin activity, increasing the chance of lateral movement and data access before the organization realizes anything is wrong.

ANY.RUN researchers found that the campaign is built on a reusable phishing framework or phish kit, allowing operators to mass-deploy event-themed lure pages across many domains.

Analysis session with fake invitation (Source : ANY.RUN).
Analysis session with fake invitation (Source : ANY.RUN).

Domain names often reference parties, invitations, or greetings, and the phishing URLs follow a consistent pattern such as https://<phish-site>/<url-pattern>/<endpoint>, with only the logo and branding swapped per target.

The underlying infrastructure also exposes fixed resource paths and a characteristic request chain: initial GET /, followed by GET /favicon.ico, GET /blocked.html, and then requests to /<url-pattern>/Image/*.png for service icons like office360.png, yahoo.png, google.png, and others.

These stable elements give SOC teams concrete hunting indicators they can use in network logs and threat intelligence platforms to link seemingly separate alerts back to the same campaign.

Full attack chain of the phishing campaign (Source : ANY.RUN).
Full attack chain of the phishing campaign (Source : ANY.RUN).

For CISOs, the core risk is that each step in this attack CAPTCHA checks, event pages, logins, and RMM installs can look normal in isolation, but together they form a path from lure to full account or remote access compromise.

If detection only happens after credentials are abused or an RMM session is active, the organization is already on the back foot.

When the user selects Gmail as the login method, a different chain is observed. First, the user is redirected to a page disguised as a Google authorization form.

Google authorization form used for the phishing attack (Source : ANY.RUN). 
Google authorization form used for the phishing attack (Source : ANY.RUN). 

Security teams should tune detection content for the shared URL and request patterns, monitor for unsanctioned RMM installations and connections, and treat event-themed invitations as high-risk when they lead to external domains or repeated login prompts.

Dynamic analysis platforms such as ANY.RUN’s interactive sandbox and Threat Intelligence Lookup can help analysts safely open suspicious invitations, observe credential and OTP capture endpoints, and pivot on shared indicators like /blocked.html, /favicon.ico, and /Image/*.png to reveal the broader campaign surface.

Follow us on Google NewsLinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.

Mayura Kathir
Mayura Kathirhttps://gbhackers.com/
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

OpenMatter Network Realigns Leadership Team to Accelerate Global Commercial Growth

Melbourne, Florida, September 10th, 2026, CyberNewswire With its Verification Architecture...

Hackers Can Turn Vulnerable LiteLLM AI Gateways Into Root Access and Cloud Credential Theft

Nearly one in 10 internet-exposed LiteLLM AI gateways accepted...

Skullcandy Dime 3 Bluetooth Flaw Lets Nearby Attackers Hijack Audio and Microphone

Skullcandy Dime 3 wireless earbuds have a serious vulnerability...

Hackers Steal Active Directory Password Hashes Without Attacking Domain Controllers Directly

Threat actors are increasingly exploiting Active Directory replication mechanisms...

Fake GTA 6 Installer Steals Browser Passwords, Discord Tokens and Crypto Data From Gamers

Threat actors are exploiting anticipation around Grand Theft Auto...

Apple Xcode Integer Underflow Flaw Lets Crafted Archives Leak Memory and Crash Builds

A recently disclosed integer-underflow vulnerability in Apple’s modern Mach-O...

Palo Alto PAN-OS Buffer Overflow Lets Attackers Execute Arbitrary Code as Root

Palo Alto Networks has announced a high-severity buffer overflow...

New Phishing Attack Uses Blob URLs to Hide Malicious Pages From Security Scanners

A phishing campaign that moves the credential-harvesting page out...

Related Articles

Recent News