# CalPhishing & Outlook Groups Abuse: Microsoft 365 Collaboration-Surface Phishing with EvilTokens AiTM and ConsentFix OAuth Token Theft

> Fortra's FIRE team is tracking active phishing campaigns that weaponize trusted Microsoft 365 collaboration features — Outlook/M365 Groups, shared files, and Outlook calendar invitations (CalPhishing via .ics) — to disguise lures as routine business workflows. Because content arrives through Microsoft's own infrastructure (e.g. groups.outlook.com), it bypasses standard email filtering and is treated as legitimate, leading to credential theft, AiTM session-token theft (EvilTokens kit), ConsentFix OAuth-consent token theft that defeats MFA, malware delivery, and data exposure.

- **Published:** 2026-06-24T00:00:00Z
- **Last reviewed:** 2026-06-24T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0932
- **ID:** TL-2026-0932
- **Severity:** HIGH
- **Category:** PHISHING
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 17 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Fortra Intelligence and Research Experts (FIRE), via security engineer Daud Jawad of Fortra's Intelligence & Threat Management team, documented (June 23, 2026) a class of phishing campaigns that hide inside routine Microsoft 365 productivity workflows rather than exploiting any software vulnerability. The tradecraft shifts malicious intent into trusted collaboration surfaces so that targets treat the interaction as normal internal business.

The attack begins when a target is added to, or invited into, an attacker-created or attacker-compromised Microsoft 365 Group. The group's name, description, or welcome message manufactures urgency and plausibility using business themes such as payroll updates, contract renewals, supplier requests, and mandatory training notices, or organizational names like 'IT Support', 'HR Updates', 'Finance Review', 'Leadership Briefing', and 'All Company'. Because the initial notification originates from a legitimate Microsoft cloud service (group membership notifications arrive from groups.outlook.com), it bypasses many email security filters and inherits the user's trust in Microsoft infrastructure.

Once group membership exists, follow-up content is delivered through the group mailbox, shared files, or — critically — Outlook calendar invitations. The CalPhishing technique uses Outlook/Microsoft 365 calendar features and iCalendar (.ics) files to place a meeting directly on a victim's calendar, in some cases without the person ever opening or even seeing the original email. Fortra describes four CalPhishing techniques that move the lure from email to calendar. The value of CalPhishing is repeated exposure and persistence: a user might ignore the initial email, then later notice the calendar event, open the invitation, read the description, click a link, or open a referenced file. Over time the event begins to resemble an unfinished work task while calendar reminders and notifications keep resurfacing it. Attackers abuse iCalendar fields directly — the SUMMARY field creates false urgency, the LOCATION field references attachments, and the DESCRIPTION field carries the scam message and links. A soft delete or move to junk does NOT remove the meeting entry from the calendar itself; only a hard delete eliminates the artifact, which both prolongs exposure and complicates incident response.

Shared files within the group's storage are used as a secondary compromise vector, delivering documents that contain a fake support process, a QR code (quishing) pointing to a credential-harvesting page, a credential-harvesting page directly, a macro lure, or remote-access instructions. Because the content is reached through a Microsoft collaboration surface, users tend to treat it as safer than a direct email attachment.

Observed email lures paired with these surfaces include 'Domain Renewal Failed' alerts impersonating GoDaddy and digital-signature requests impersonating DocuSign, leading to brand-spoofed credential-harvesting pages. Attackers chain redirects and abuse Cloudflare to hide the final landing infrastructure from security scanners, and AI automation is suspected behind the high volume of distribution.

The campaigns are notable for defeating multi-factor authentication. Rather than only harvesting passwords, attackers use adversary-in-the-middle (AiTM) tradecraft and the EvilTokens phishing kit — sold on Telegram — to steal live session tokens, allowing account takeover even when MFA is enabled. A related technique, ConsentFix (a device-code / OAuth consent-grant phishing approach), tricks users into authorizing an attacker application, yielding application access/refresh tokens that provide MFA-resistant, persistent access to the victim's Microsoft 365 environment.

The defining defensive challenge is cross-surface visibility: activity is spread across email, Microsoft 365 Groups, shared files, and calendar events, and standard email filtering alone is insufficient. Defenders must treat unexpected groups, meetings, and shared files with the same caution as unexpected emails — especially when the theme is urgent, administrative, or account related — and must investigate the full chain (who created the group, which users were added, what files were uploaded, and what calendar artifacts linger after the original email is removed).

## MITRE ATT&CK

- T1598 Phishing for Information
- T1585 Establish Accounts
- T1588 Obtain Capabilities
- T1583 Acquire Infrastructure
- T1566 Phishing
- T1204 User Execution
- T1098 Account Manipulation
- T1684.001 Impersonation
- T1550 Use Alternate Authentication Material
- T1539 Steal Web Session Cookie
- T1528 Steal Application Access Token
- T1056 Input Capture
- T1114 Email Collection

## Sources

- [Phishing hides in routine Microsoft 365 workflows](https://www.helpnetsecurity.com/2026/06/23/microsoft-365-collaboration-features-phishing/)
- [Techronicler: CalPhishing and ConsentFix — The New Playbook for Persistent, Trust-Based Cyber Attacks](https://www.fortra.com/resources/articles/techronicler-calphishing-and-consentfix-new-playbook-persistent-trust-based)
- [CalPhishing Scam Uses EvilTokens Kit, Outlook Invites to Steal M365 Sessions](https://hackread.com/calphishing-eviltokens-kit-outlook-invites-m365/)
- [CalPhishing Campaigns Use Outlook Calendar Invites to Deliver Persistent Phishing Lures](https://gbhackers.com/calphishing-campaigns-use-outlook-calendar/)
- [Hackers Abuse Outlook Groups and Microsoft 365 Collaboration Features for Phishing Attacks](https://cyberpress.org/outlook-groups-fuel-phishing/)
- [New Phishing Attack Abuses Outlook and Microsoft 365 Groups Features to Attack Users](https://cybersecuritynews.com/new-phishing-attack-abuses-outlook-and-microsoft-365-groups/)
- [Microsoft 365's Most Trusted Features Are Being Weaponized Against Corporate Users](https://the420.in/microsoft-365-groups-phishing-attack-security-update/)
- [Phishing in Microsoft 365: How Cybersecurity Threats Hide in Daily Workflows](https://www.news4hackers.com/phishing-in-microsoft-365-how-cybersecurity-threats-hide-in-daily-workflows/)
- [MITRE ATT&CK T1566.003 — Phishing: Spearphishing via Service](https://attack.mitre.org/techniques/T1566/003/)
- [MITRE ATT&CK T1539 — Steal Web Session Cookie](https://attack.mitre.org/techniques/T1539/)
- [MITRE ATT&CK T1528 — Steal Application Access Token](https://attack.mitre.org/techniques/T1528/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0932
