Researchers at Fortra are tracking a new variant of calendar phishing in which threat actors trick employees into sharing meeting links internally.
The attackers pose as prospective customers and contact non-sales employees, asking to be directed to a sales representative in order to discuss a business opportunity. The attacker then sends the employee a meeting link to forward to a sales contact.
The attack takes place as follows:
- “Prospect pretext. An external sender claims they want to buy and contacts a non-sales employee for the right point of contact.
- Helpful response. The employee engages, asks for availability, and confirms that they can route the request.
- Internal handoff. The sender provides a meeting-booking link and asks for it to be forwarded to sales.
- Trusted delivery. Sales representative receives the email containing a ‘book a meeting’ button embedded with a link, forwarded from a known colleague. The forward changes the recipient’s risk calculation.
- Calendar pivot. The booking page asks the user to choose a date and time, then introduces a Microsoft 365 work-or-school sign-in prompt, framed as necessary to complete or sync the booking."
In this last step, the sales employee is asked to enter their Microsoft 365 credentials, which is the end goal of the attack. The researchers note that this lengthy and indirect attack chain increases the effectiveness of the social engineering tactics. The employee who receives the link is unlikely to click it, since the meeting isn’t meant for them, and the sales employee is more likely to trust the link since it was forwarded by a known coworker.
“What makes this effective is not a clever email alone,” Fortra says. “It is the trust chain: external sender, helpful employee, internal forward, sales recipient, booking page, sign-in prompt. Every step is individually familiar, so the full chain does not feel like a phishing chain.”
Fortra has the story: https://www.fortra.com/blog/calphishing-through-trust-chain
