CalPhishing & Outlook Groups Abuse: Microsoft 365 Collaboration-Surface Phishing with EvilTokens AiTM and ConsentFix OAuth Token Theft — Threadlinqs Intelligence
As of 2026-06-24, CalPhishing & Outlook Groups Abuse: Microsoft 365 Collaboration-Surface Phishing with EvilTokens AiTM and ConsentFix OAuth Token Theft is a high-severity phishing threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 17 indicators of compromise.
Threat ID: TL-2026-0932 · Severity: HIGH · Status: ACTIVE · Category: PHISHING
Fortra's FIRE team is tracking active phishing campaigns that weaponize trusted Microsoft 365 collaboration features — Outlook/M365 Groups, shared files, and Outlook calendar invitations (CalPhishing
Fortra Intelligence and Research Experts (FIRE), via security engineer Daud Jawad of Fortra's Intelligence & Threat Management team, documented (June 23, 2026) a class of phishing campaigns that hide inside routine Microsoft 365 productivity workflows rather than exploiting any software vulnerability. The tradecraft shifts malicious intent into trusted collaboration surfaces so that targets treat the interaction as normal internal business.
The attack begins when a target is added to, or invited into, an attacker-created or attacker-compromised Microsoft 365 Group. The group's name, description, or welcome message manufactures urgency and plausibility using business themes such as payroll updates, contract renewals, supplier requests, and mandatory training notices, or organizational names like 'IT Support', 'HR Updates', 'Finance Review', 'Leadership Briefing', and 'All Company'. Because the initial notification originates from a legitimate Microsoft cloud service (group membership notifications arrive from groups.outlook.com), it bypasses many email security filters and inherits the user's trust in Microsoft infrastructure.
Once group membership exists, follow-up content is delivered through the group mailbox, shared files, or — critically — Outlook calendar invitations. The CalPhishing technique uses Outlook/Microsoft 365 calendar features and iCalendar (.ics) files to place a meeting directly on a victim's calendar, in some cases without the person ever opening or even seeing the original email. Fortra describes four CalPhishing techniques that move the lure from email to calendar. The value of CalPhishing is repeated exposure and persistence: a user might ignore the initial email, then later notice the calendar event, open the invitation, read the description, click a link, or open a referenced file. Over time the event begins to resemble an unfinished work task while calendar reminders and notifications keep resurfacing it. Attackers abuse iCalendar fields directly — the SUMMARY field creates false urgency, the LOCATION field references attachments, and the DESCRIPTION field carries the scam message and links. A soft delete or move to junk does NOT remove the meeting entry from the calendar itself; only a hard delete eliminates the artifact, which both prolongs exposure and complicates incident response.
Shared files within the group's storage are used as a secondary compromise vector, delivering documents that contain a fake support process, a QR code (quishing) pointing to a credential-harvesting page, a credential-harvesting page directly, a macro lure, or remote-access instructions. Because the content is reached through a Microsoft collaboration surface, users tend to treat it as safer than a direct email attachment.
Observed email lures paired with these surfaces include 'Domain Renewal Failed' alerts impersonating GoDaddy and digital-signature requests impersonating DocuSign, leading to brand-spoofed credential-harvesting pages. Attackers chain redirects and abuse Cloudflare to hide the final landing infrastructure from security scanners, and AI automation is suspected behind the high volume of distribution.
The campaigns are notable for defeating multi-factor authentication. Rather than only harvesting passwords, attackers use adversary-in-the-middle (AiTM) tradecraft and the EvilTokens phishing kit — sold on Telegram — to steal live session tokens, allowing account takeover even when MFA is enabled. A related technique, ConsentFix (a device-code / OAuth consent-grant phishing approach), tricks users into authorizing an attacker application, yielding application access/refresh tokens that provide MFA-resistant, persistent access to the victim's Microsoft 365 environment.
The defining defensive challenge is cross-surface visibility: activity is spread across email, Microsoft 365 Groups, shared files, and calendar events, and standard email filtering alone is insufficient. Defenders must treat unexpected grou
Target sectors: enterprise, finance, human-resources, information-technology, professional-services
Target regions: Global
Detections & IOCs
As of 2026-07-20, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 17 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
PHISHING, HIGH, threat intelligence, cybersecurity, T1598, T1585, T1588, T1583, T1583, T1566, T1566, T1566, T1204, T1204