// ZDNET — CYBERSECURITY
Fake calendar invites can infect your system, and they’re surging – how to protect yourself
These invites sneak past your security software to embed themselves in your calendar. But you can thwart them before they do any damage.
Have you ever received a calendar invite via email that turned out to be fake and even malicious? I’ve gotten these in Microsoft Outlook. Many email programs automatically add an invite to your calendar before you can even accept or decline it. That means you may not be aware that the event information is now in your calendar, waiting for you to access it.
A new report from cybersecurity firm Sublime highlights a dramatic rise in these calendar-based malware attacks. Over the past few months, such attacks rose by 282% in June over the prior month, by 338% in July, and by a whopping 1,216% in August. For September, the firm projects a 2,852% increase over August.
Also: Inside Google’s faster Chrome patch strategy to block AI attacks on your browser
These scams are gaining in popularity for a couple of reasons. They’re relatively easy to pull off. And they take advantage of a default setting for calendar invites in many email programs.
To pull off these attacks, scammers use a technique that Sublime calls ICS phishing. Part of the iCalendar standard, an ICS file contains the details for a meeting or appointment invitation. In programs such as Microsoft Outlook, Gmail, and Apple Mail, an ICS file sent via email can automatically be added to your calendar before you even decide to accept or decline the invite.
These types of scams prove successful for several reasons.
Also: Windows 11 out-of-band update fixes audio glitch and other bugs – grab it now
“What makes these attacks successful is the implied trust — both systems involved and of the invitation itself,” John Gallagher, VP at cyber hygiene provider Viakoo, told ZDNET. “The attacker is assuming default settings are in place, and that calendar invites are not as suspect as email phishing is. The danger is with what is inside the invite; links or QR codes can compromise the victim’s system, and even rejecting the invite can send the attacker information on the email address being valid.”
One recent attack highlighted by Sublime used a Google Calendar invite to deliver a link to a malicious remote monitoring and management (RMM) payload. The email itself employed a known financial lure tactic. In this case, the message tempted users with an alleged credit against a recent invoice, inviting them to a meeting to discuss the matter.