Threat reportPhishingTL-2026-0932

CalPhishing & Outlook Groups Abuse: Microsoft 365 Collaboration-Surface Phishing with EvilTokens AiTM and ConsentFix OAuth Token Theft

highACTIVE

CalPhishing & Outlook Groups Abuse (TL-2026-0932), also tracked as CalPhishing, is a high-severity phishing campaign, first published 2026-06-24. It has no confirmed attribution, affects Microsoft Microsoft 365 (Outlook, Microsoft 365 Groups, Outlook, maps to 13 MITRE ATT&CK techniques (T1056, T1098, T1114), and is covered by 9 detection rules and 17 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
13MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
17Indicators of compromise

Key facts for TL-2026-0932

Threat ID
TL-2026-0932
Also known as
CalPhishing, Outlook Groups Phishing, ConsentFix
Severity
HIGH
Status
ACTIVE
Category
PHISHING
First published
Last reviewed
Attribution confidence
NONE
Motivation
FINANCIAL
Target sectors
enterprise, finance, human-resources, information-technology, professional-services
Target regions
Global
Detection rules
9
Indicators of compromise
17

Malware and tooling in CalPhishing & Outlook Groups Abuse

Malware and tooling: EvilTokens

How CalPhishing & Outlook Groups Abuse works

Fortra's FIRE team is tracking active phishing campaigns that weaponize trusted Microsoft 365 collaboration features — Outlook/M365 Groups, shared files, and Outlook calendar invitations (CalPhishing via .ics) — to disguise lures as routine business workflows. Because content arrives through Microsoft's own infrastructure (e.g. groups.outlook.com), it bypasses standard email filtering and is treated as legitimate, leading to credential theft, AiTM session-token theft (EvilTokens kit), ConsentFix OAuth-consent token theft that defeats MFA, malware delivery, and data exposure.

Fortra Intelligence and Research Experts (FIRE), via security engineer Daud Jawad of Fortra's Intelligence & Threat Management team, documented (June 23, 2026) a class of phishing campaigns that hide inside routine Microsoft 365 productivity workflows rather than exploiting any software vulnerability. The tradecraft shifts malicious intent into trusted collaboration surfaces so that targets treat the interaction as normal internal business.

The attack begins when a target is added to, or invited into, an attacker-created or attacker-compromised Microsoft 365 Group. The group's name, description, or welcome message manufactures urgency and plausibility using business themes such as payroll updates, contract renewals, supplier requests, and mandatory training notices, or organizational names like 'IT Support', 'HR Updates', 'Finance Review', 'Leadership Briefing', and 'All Company'. Because the initial notification originates from a legitimate Microsoft cloud service (group membership notifications arrive from groups.outlook.com), it bypasses many email security filters and inherits the user's trust in Microsoft infrastructure.

Once group membership exists, follow-up content is delivered through the group mailbox, shared files, or — critically — Outlook calendar invitations. The CalPhishing technique uses Outlook/Microsoft 365 calendar features and iCalendar (.ics) files to place a meeting directly on a victim's calendar, in some cases without the person ever opening or even seeing the original email. Fortra describes four CalPhishing techniques that move the lure from email to calendar. The value of CalPhishing is repeated exposure and persistence: a user might ignore the initial email, then later notice the calendar event, open the invitation, read the description, click a link, or open a referenced file. Over time the event begins to resemble an unfinished work task while calendar reminders and notifications keep resurfacing it. Attackers abuse iCalendar fields directly — the SUMMARY field creates false urgency, the LOCATION field references attachments, and the DESCRIPTION field carries the scam message and links. A soft delete or move to junk does NOT remove the meeting entry from the calendar itself; only a hard delete eliminates the artifact, which both prolongs exposure and complicates incident response.

Shared files within the group's storage are used as a secondary compromise vector, delivering documents that contain a fake support process, a QR code (quishing) pointing to a credential-harvesting page, a credential-harvesting page directly, a macro lure, or remote-access instructions. Because the content is reached through a Microsoft collaboration surface, users tend to treat it as safer than a direct email attachment.

Observed email lures paired with these surfaces include 'Domain Renewal Failed' alerts impersonating GoDaddy and digital-signature requests impersonating DocuSign, leading to brand-spoofed credential-harvesting pages. Attackers chain redirects and abuse Cloudflare to hide the final landing infrastructure from security scanners, and AI automation is suspected behind the high volume of distribution.

The campaigns are notable for defeating multi-factor authentication. Rather than only harvesting passwords, attackers use adversary-in-the-middle (AiTM) tradecraft and the EvilTokens phishing kit — sold on Telegram — to steal live session tokens, allowing account takeover even when MFA is enabled. A related technique, ConsentFix (a device-code / OAuth consent-grant phishing approach), tricks users into authorizing an attacker application, yielding application access/refresh tokens that provide MFA-resistant, persistent access to the victim's Microsoft 365 environment.

The defining defensive challenge is cross-surface visibility: activity is spread across email, Microsoft 365 Groups, shared files, and calendar events, and standard email filtering alone is insufficient. Defenders must treat unexpected groups, meetings, and shared files with the same caution as unexpected emails — especially when the theme is urgent, administrative, or account related — and must investigate the full chain (who created the group, which users were added, what files were uploaded, and what calendar artifacts linger after the original email is removed).

MITRE ATT&CK techniques used in TL-2026-0932

Credential Access

T1056 Input Capture; T1528 Steal Application Access Token; T1539 Steal Web Session Cookie

Persistence

T1098 Account Manipulation

Collection

T1114 Email Collection

Execution

T1204 User Execution

lateral-movement

T1550 Use Alternate Authentication Material

Initial Access

T1566 Phishing

Resource Development

T1583 Acquire Infrastructure; T1585 Establish Accounts; T1588 Obtain Capabilities

Reconnaissance

T1598 Phishing for Information

stealth

T1684.001 Impersonation

Affected products and versions in CalPhishing & Outlook Groups Abuse

  • Microsoft — Microsoft 365 (Outlook, Microsoft 365 Groups, Outlook Calendar, SharePoint/Group shared files)
    Vulnerable versions: Microsoft 365 / Outlook collaboration features (cloud)

Remediation for CalPhishing & Outlook Groups Abuse

Immediate actions

  • Treat unexpected Microsoft 365 Group additions, calendar invitations, and shared files with the same caution as unsolicited email, especially when the theme is urgent, administrative, payroll, contract, or account related.
  • Hard-delete (not soft-delete or move-to-junk) suspicious calendar events — soft delete leaves the .ics meeting entry on the calendar where reminders keep resurfacing it.
  • When investigating, scope the full cross-surface chain: who created the group, which internal users were added, what files were uploaded to shared storage, and what calendar artifacts remain after the originating email is removed.
  • Hunt Entra ID sign-in logs for AiTM/session-token-theft indicators (impossible travel, unfamiliar session tokens, sign-ins replaying stolen cookies) tied to recently added group members.

Workarounds

  • Scrutinize or block external Microsoft 365 Group notifications (groups.outlook.com) at the gateway where business need does not require them.
  • Disable automatic processing/auto-add of meeting invitations to calendars where policy allows.
  • Block known credential-harvesting redirect infrastructure and inspect Cloudflare-fronted redirect chains in proxy logs.

Longer-term hardening

  • Deploy cross-surface visibility that correlates email, M365 Groups, shared files, and calendar events into a single attack chain rather than relying on standard email filtering alone.
  • Restrict who can create Microsoft 365 Groups and require approval/governance for external group membership and group naming.
  • Enforce phishing-resistant MFA (FIDO2 / passkeys / certificate-based) and Conditional Access to blunt AiTM session-token theft and ConsentFix OAuth abuse.
  • Restrict end-user OAuth application consent (admin consent workflow) to defeat ConsentFix device-code / consent-grant token theft.
  • User awareness training covering calendar-based (CalPhishing) and collaboration-surface lures, QR-code (quishing) phishing, and brand-impersonation (GoDaddy/DocuSign) themes.

Timeline of CalPhishing & Outlook Groups Abuse

  • CalPhishing campaigns observed active in early 2026, identified by Fortra Intelligence and Research Experts (FIRE).
  • Brand-impersonation lures observed: 'Domain Renewal Failed' (fake GoDaddy) and digital-signature requests (fake DocuSign), with Cloudflare-fronted redirect chains evading scanners.
  • ConsentFix (device-code / OAuth consent-grant phishing) documented stealing application/session tokens for MFA-resistant, persistent access.
  • EvilTokens phishing kit, sold on Telegram, documented automating AiTM session-token theft to bypass MFA.
  • Four distinct CalPhishing techniques documented moving the lure from email into Outlook calendar via .ics invitations.
  • Help Net Security and multiple outlets reported the campaign, describing CalPhishing, ConsentFix, and the EvilTokens AiTM kit.
  • Fortra (security engineer Daud Jawad, Intelligence & Threat Management) publicly detailed the abuse of Microsoft 365 collaboration features (Outlook Groups, shared files, calendar) for phishing.
  • Threat catalogued as TL-2026-0932 in the Threadlinqs Intelligence Platform for detection development and threat hunting.

Sources cited for CalPhishing & Outlook Groups Abuse

Detection coverage for TL-2026-0932

As of 2026-06-24, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0932 across Splunk SPL, Microsoft KQL and Sigma, covering 17 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
17 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats