Tactic or Technique: ICS Phishing

ICS phishing is a deceptive attack technique that uses calendar invite files (.ics) to deliver phishing content in a way that feels routine and trustworthy. These invites often appear as legitimate meeting requests from platforms like Microsoft 365 or Google Workspace, making them easy to accept without suspicion.
What makes this technique especially effective is how calendar systems handle invitations. In many environments, events can be automatically added to a user's calendar, giving attackers a second delivery channel beyond the inbox.
Once on the calendar, these events can contain phishing links, malicious attachments, or urgent instructions. Because calendar entries are persistent and trusted, the attack can continue even after the email is removed, increasing the likelihood of credential theft, malware downloads, or other compromise.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Attachment: ICS calendar file with suspicious UID domain
22h ago
Sep 29th, 2026
Sublime Security
Attachment: Oversized guest-list calendar invite with voicemail lure
2d ago
Sep 28th, 2026
Sublime Security
Attachment: ICS calendar invite hiding credential theft
2d ago
Sep 28th, 2026
Sublime Security
Attachment: Oversized guest-list calendar invite with purchase order lure
2d ago
Sep 28th, 2026
Sublime Security
Attachment: ICS with Suspicious Office 365 app authorization (OAuth) link
2d ago
Sep 28th, 2026
Sublime Security
Attachment: ICS calendar file with legal language
2d ago
Sep 28th, 2026
Sublime Security
Attachment: ICS calendar invite with bid/RFP lure and suspicious link
2d ago
Sep 28th, 2026
Sublime Security
Attachment: ICS voicemail lure with suspicious link
2d ago
Sep 28th, 2026
Sublime Security
Attachment: ICS file with credential theft indicators
2d ago
Sep 28th, 2026
Sublime Security
Attachment: ICS invite meeting lure
2d ago
Sep 28th, 2026
Sublime Security
Attachment: ICS calendar with suspicious link Leading to minimal JS landing page
2d ago
Sep 28th, 2026
Sublime Security
Attachment: ICS calendar invite with hex-encoded recipient in link
2d ago
Sep 28th, 2026
Sublime Security
Attachment: ICS link with valueless base64 query parameter
2d ago
Sep 28th, 2026
Sublime Security
Link: Google Calendar invite linking to an open redirect from an untrusted freemail sender
2d ago
Sep 28th, 2026
Sublime Security
Attachment: Calendar invite with suspicious link leading to an open redirect
2d ago
Sep 28th, 2026
Sublime Security
Attachment: HTML smuggling with atob and high entropy via calendar invite
7d ago
Sep 23rd, 2026
Sublime Security
Attachment: ICS file with excessive custom properties
26d ago
Sep 4th, 2026
Sublime Security
Callback phishing via calendar invite
1mo ago
Aug 7th, 2026
Sublime Security
Attachment: ICS calendar file with suspicious product identifier
2mo ago
Jul 27th, 2026
Sublime Security
Attachment: ICS file with AWS Lambda URL
2mo ago
Jul 16th, 2026
Sublime Security