CalPhishing: Phishing Campaign Abusing Microsoft 365 Groups and Outlook Calendar Invites for Persistent Lures and EvilTokens Device-Code Session Theft — Threadlinqs Intelligence
As of 2026-06-24, CalPhishing: Phishing Campaign Abusing Microsoft 365 Groups and Outlook Calendar Invites for Persistent Lures and EvilTokens Device-Code Session Theft is a high-severity phishing threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 19 indicators of compromise.
Threat ID: TL-2026-0930 · Severity: HIGH · Status: ACTIVE · Category: PHISHING
Fortra's Intelligence and Research Experts (FIRE) team documented an active 2026 phishing campaign that abuses legitimate Microsoft 365 Groups and Outlook calendar features rather than a software
Fortra's Intelligence and Research Experts (FIRE) team identified a phishing campaign, active in early-to-mid 2026, that represents a shift from traditional inbox spoofing toward abuse of trusted Microsoft 365 collaboration workflows. Because the activity runs through Microsoft's own infrastructure and services rather than a spoofed sender, it evades much of the source-validation logic that both email security gateways and phishing-awareness training rely on.
Initial access begins when a target is added to, or invited into, an attacker-created or attacker-controlled Microsoft 365 Group. Group names, descriptions, and welcome messages are crafted to blend in with internal communications and to manufacture urgency or routine context, using themes such as 'IT Support,' 'HR Updates,' 'Finance Review,' 'Leadership Briefing,' and 'All Company,' or payroll updates, contract renewals, supplier requests, mandatory training, and invoice review. A single group join simultaneously grants the attacker a foothold across the victim's group mailbox, shared file storage, and calendar surface.
The campaign's signature component is CalPhishing (Calendar Phishing). A malicious calendar event in iCalendar (.ics) format is delivered to the victim's Outlook calendar. As soon as Outlook processes the .ics file it automatically creates a 'tentative' meeting on the calendar without any user interaction, and this occurs before email security tools scan the attachment. The attacker weaponizes standard calendar fields: SUMMARY to create urgency, LOCATION to reference attached files and appear legitimate, and DESCRIPTION to carry the phishing message and instructions (links, sign-in prompts, file references). The core security gap is post-delivery persistence: a soft delete, move to junk, or remediation of the originating email does not remove the meeting entry from the calendar itself, so scheduled reminders keep resurfacing the lure. Over time the event begins to look like an unfinished work task, and recurring reminders apply sustained psychological pressure that brings the malicious content back into view long after the email is gone.
Payload delivery across the group surfaces includes credential-harvesting links and sign-in prompts, QR codes pointing to credential-harvesting pages, macro-enabled documents shared through group collaboration, fake support processes inside shared documents, and themed lures including fake Microsoft 365 / domain renewal alerts mimicking GoDaddy and fake digital-signature requests mimicking DocuSign. Rather than harvesting static passwords, the campaign frequently pivots to token theft via device-code phishing (referred to with the ConsentFix technique), allowing the attacker to capture a valid Microsoft 365 session token and authenticate as the user even when MFA is enabled. This workflow is automated by the EvilTokens phishing kit, which is sold on Telegram and packages device-code/consent phishing and session-token capture so operators can compromise accounts despite multi-factor authentication.
Reported outcomes include credential theft, session/token capture, MFA bypass via stolen application access tokens, malware delivery, broad data exposure across the network, and follow-on social engineering. Defense requires looking well beyond initial email delivery: tracing the full chain (who created the group, who was added, what files were shared, and whether calendar entries remain after mail remediation) and achieving cross-surface visibility spanning mail, calendar, files, and identity/token activity.
Target sectors: enterprise, government, financial, healthcare, technology
Target regions: Global
Detections & IOCs
As of 2026-07-20, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 19 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
PHISHING, HIGH, threat intelligence, cybersecurity, T1598, T1598.003, T1583.001, T1585.003, T1588.002, T1608.005, T1566, T1566.001, T1566.002, T1199