VỮNG MÃI MỘT NIỀM TIN

FROM MEETING INVITES TO MALWARE: HOW CALENDAR FILES BECOME A BACKDOOR FOR EMAIL ATTACKS

  • 08/04/2026

 

A new cyberattack trend is rapidly spreading worldwide as threat actors abuse iCalendar (.ics) files—long considered harmless—to distribute malware, steal data, and even exploit zero-day vulnerabilities. Security researchers warn that this technique can bypass most traditional email security controls.




ICS Files: From Harmless Schedules to Attack Vectors

ICS files are widely used to share meeting schedules via Outlook, Google Calendar, and Apple iCal. Because they are plain-text calendar files, many security systems do not inspect them deeply.

Attackers exploit this trust by embedding malicious links, hidden binaries, or encoded payloads within event descriptions, locations, or attachments. Once a user opens or accepts the invitation, the attack chain begins—without downloading any executable file.

According to Sublime Security, Cymulate, and NCC Group, ICS-based attacks have become the third most common email phishing method, with up to 59% of malicious ICS files bypassing secure email gateways (SEGs).


Why Calendar Files Easily Bypass Email Security

Most email security tools focus on high-risk file types such as executables, archives, or macro-enabled documents. ICS files, classified as text/calendar, often evade deep inspection.

More critically, platforms like Outlook and Google Calendar may automatically process calendar invitations, creating draft events even when the email is flagged as spam. As a result, malicious content can persist inside the user’s calendar without their awareness.

Some security teams describe this as dual-entry exposure—email and calendar—significantly increasing phishing success rates.


Real-World Attack Campaigns (2024–2025)

Zimbra Zero-Day Exploitation (CVE-2025-27915)
In June 2025, a zero-day vulnerability in Zimbra allowed JavaScript execution when opening ICS files. The campaign targeted Brazilian military organizations using spoofed diplomatic emails and base64-encoded payloads to steal credentials and bypass MFA.

APT41 Abusing Google Calendar as C2 Infrastructure

Several reports indicate that APT41 used Google Calendar as a command-and-control channel, hiding commands in event descriptions. Victims were infected via malicious LNK files disguised as PDFs.

Mass Google Calendar Phishing Campaign
Check Point documented over 300 organizations targeted through fake calendar invitations impersonating trusted contacts. Embedded links redirected victims to fake banking and cryptocurrency platforms.

Outlook Exploits via DDE and CVE-2025-32705
Certain Outlook vulnerabilities allowed malware execution after users simply confirmed a calendar prompt, leading to NTLM credential theft or remote code execution.


Recommended Mitigation Measures

Security experts urge organizations to treat ICS files as high-risk attachments. Recommended actions include:

  • Disabling automatic calendar event creation from unknown senders

  • Enforcing deep inspection of ICS files and embedded attachments

  • Monitoring calendar systems for anomalous activity

  • Training employees to recognize meeting-invite phishing

End users should avoid opening unsolicited calendar invites, refrain from clicking embedded links, and always verify the sender’s identity.


Conclusion

ICS-based attacks are surging because they exploit user trust in familiar platforms and blind spots in email security systems. With nearly 60% bypass rates and increasing targeting of financial, military, and government organizations, calendar files are emerging as a dangerous new attack vector.

Sources: Rapid7, Forbes


Partner