Tactic or Technique: ICS Phishing

ICS phishing is a deceptive attack technique that uses calendar invite files (.ics) to deliver phishing content in a way that feels routine and trustworthy. These invites often appear as legitimate meeting requests from platforms like Microsoft 365 or Google Workspace, making them easy to accept without suspicion.
What makes this technique especially effective is how calendar systems handle invitations. In many environments, events can be automatically added to a user's calendar, giving attackers a second delivery channel beyond the inbox.
Once on the calendar, these events can contain phishing links, malicious attachments, or urgent instructions. Because calendar entries are persistent and trusted, the attack can continue even after the email is removed, increasing the likelihood of credential theft, malware downloads, or other compromise.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Callback phishing via calendar invite
16d ago
May 12th, 2026
Sublime Security
Attachment: ICS calendar file with base64 encoded recipient address in URL parameters
16d ago
May 12th, 2026
Sublime Security
Service abuse: Google Calendar notification with callback scam language
1mo ago
Apr 28th, 2026
Sublime Security
Attachment: ICS file with AWS Lambda URL
1mo ago
Apr 28th, 2026
Sublime Security
Attachment: ICS with embedded document
1mo ago
Apr 28th, 2026
Sublime Security
Attachment: Calendar invite with Google redirect and invoice request
1mo ago
Apr 28th, 2026
Sublime Security
Attachment: ICS file with non-Gregorian calendar scale
1mo ago
Apr 28th, 2026
Sublime Security
Attachment: Calendar invite from recently registered domain
1mo ago
Apr 28th, 2026
Sublime Security
Attachment: ICS calendar with embedded file from internal sender with SPF failure
1mo ago
Apr 28th, 2026
Sublime Security
Attachment: ICS with embedded Javascript in SVG file
1mo ago
Apr 28th, 2026
Sublime Security
Attachment: Calendar invite with suspicious link leading to an open redirect
1mo ago
Apr 28th, 2026
Sublime Security
Link: Google Calendar invite linking to an open redirect from an untrusted freemail sender
1mo ago
Apr 28th, 2026
Sublime Security
Non-RFC compliant calendar files from unsolicited sender
1mo ago
Apr 28th, 2026
Sublime Security
Attachment: HTML smuggling with atob and high entropy via calendar invite
1mo ago
Apr 28th, 2026
Sublime Security
Attachment: HTML smuggling with eval and atob via calendar invite
1mo ago
Apr 28th, 2026
Sublime Security
Attachment: ICS file with meeting prefix
1mo ago
Apr 28th, 2026
Sublime Security
Attachment: ICS with employee policy review lure
1mo ago
Apr 28th, 2026
Sublime Security
Attachment: Calendar file with invisible Unicode characters
1mo ago
Apr 28th, 2026
Sublime Security
Attachment: ICS file with excessive custom properties
1mo ago
Apr 28th, 2026
Sublime Security