Calendar-based attacks have been steadily increasing since gaining popularity last year, earning a spot in the hot trends portion of our 2026 Sublime Email Threat Research Report. Since August, though, our Detection Engineers have observed a massive increase in attacks using calendar invites as a delivery mechanism. Here are the monthly increases:
- June: 282% over May
- July: 338% over June
- August: 1,216% over July
- 1st half of September: 1,426% over full month of August
- September (projected): 2,852% over August
The slow and steady increases in June and July are what we have observed since ICS phishing first started gaining popularity. The jumps in August and September appear to be indicators that this attack type has finally hit the mainstream. To really drive that point home, the increase from May to September is projected to be ~33,000%.
Why calendar attacks are so popular
These attacks are growing in popularity because of how effective they are evading security. Here are some reasons:
- Two-pronged: Meeting invitations are sent to both calendars and inboxes. This means twice the exposure for targets.
- Security gap exploiting: Most email security systems are only built to stop these types of attacks in inboxes, not calendars. This creates a unique security gap where the email security scanner catches the email, but the invite still reaches the target’s calendar.
- Trusted services and infrastructure: The majority of attacks are sent over Google infrastructure (Gmail via Google Calendar). The next most comes over Microsoft infrastructure. These are generally trusted services and infrastructures.
- Free services and infrastructure: Most of these attacks abuse free services, meaning the cost for adversaries is $0.
If you are a Sublime customer, you’re protected from these dual attacks. If you’re not, check out our ICS phishing playbook that can be applied to other email security providers.
Example calendar attack: RMM via ICS
We recently put out a blog about a variety of different calendar services we’ve seen abused for ICS phishing attacks, but invitations can also be used to deliver other types of payloads. We’re going to look at a recent attack that used a Google Calendar invite to deliver a link to a maliciously-configured remote monitoring and management (RMM) payload. The attack starts with a simple message with a financial lure:

This meeting invitation was sent from a Gmail account, meaning it would likely not be blocked based on domain. Depending on the configuration of the receiving client, aside from not being automatically blocked from the inbox, it would likely be automatically added to the target’s inbox:

Because email and calendar operate over different protocols, there is a non-zero chance that even if the target’s email security solution catches the phishing email, the meeting would still land on the target’s calendar.
If the target clicks the payload link in the email or the calendar entry, they’re taken to a page hosted on framer[.]website. Framer offers a free plan, lowering the barrier of entry for abuse.

Once at the payload delivery page, the target is directed to click VIEW HERE to download their credit note. We have observed that properly configured Microsoft environments will block the download of this file. In Microsoft environments with less security, or in the case the target overrides the block, a ~10MB ScreenConnect.ClientSetup.msi is downloaded.
ScreenConnect is one of a handful of legitimate RMMs that have become popular with attackers. We have previously reported on ScreenConnect being abused as malware, including an interesting post on an advanced fake Zoom installer.


Along with the installation files, the MSI also contains configuration information to repurpose the legitimate ScreenConnect tool as a malicious C2 for adversarial use. Malicious RMM attacks have become fairly common (and well documented), so we’re not going to dig into the payload any further.
If you want to learn about a more novel RMM attack, check out this post about an adversary that used the ClickFix technique to deliver a malicious NetSupport payload.
Rent free in plain sight
Take note of the amount of free, legitimate tools the adversary used to deliver the payload to an undisclosed number of targets:
- Gmail: The attack was sent from a free
gmail[.]comaccount. The ubiquity of this domain provides instant cover from denylists. - Google Calendar: The Google Calendar invite came over trusted Google infrastructure. Additionally, calendar entries are typically not triaged by email security solutions.
- Google redirect: Google Calendar automatically re-writes URLs in meeting invitation emails to redirect off of
google[.]com. While the link in the email above resolves to aframer[.]websitesite (a useful signal), the automatically re-written URL is:
- Framer: Framer offers a free tier for building websites.
- ScreenConnect: ScreenConnect offers a 14-day free trial of their RMM.
Detection signals
Sublime's AI-powered detection engine prevents these attacks. Some of the top signals from this example are:
- Suspicious CTA: The invitation includes a link to
secured-website.framer[.]website/credit-note. The domain indicated a free website builder and the subdomain is an attempt at authority. - Suspicious sender: The invitation was sent from a first-time sender using a Gmail account even though the message content appears to be business related.
- Financial urgency: The message references a fake, recent $1,109.08 payment that requires action, both common manipulation tactics.
ASA, Sublime’s Autonomous Security Analyst, flagged this email as malicious and remediated the associated calendar entry. Here is ASA’s analysis summary:

ICS on the rise
Calendar-based attacks are popular because they’re effective against traditional email security solutions. That’s why Sublime offers protection that follows the trail from malicious email to malicious calendar entry.
If you enjoyed this Attack Spotlight, be sure to check our blog every week for new blogs, subscribe to our RSS feed, or sign up for our monthly newsletter. Our newsletter covers the latest blogs, detections, product updates, and more.
Read more Attack Spotlights:
Get the latest
Sublime releases, detections, blogs, events, and more directly to your inbox.






.avif)