Laufender Phishing-Angriff missbraucht Google Kalender, um Spam-Filter zu umgehen

Teilen:

An ongoing phishing scam is abusing Google Calendar invites and Google Drawings pages to steal credentials while bypassing spam filters.

According to Check Point, which has been monitoring the phishing attack, the threat actors have targeted 300 brands with over 4,000 emails sent in four weeks.

Check Point told BleepingComputer that the attacks targeted a broad range of companies, including educational institutions, healthcare services, building companies, and banks.

The attack starts with the threat actors using Google Calendar to send meeting invites that look pretty innocuous, especially if you recognize some of the other guests.

Embedded in these invites, as shown below, is a link that leads to Google Forms or Google Drawings that prompt the user to click another link, typically disguised as a reCaptcha or support button.

Example Google Calender invite phishing email
Example Google Calender invite phishing email
Source: Check Point

Email Researchers at Check Point told BleepingComputer that by utilizing the Google Calendar services to initiate the phishing invites, they bypass spam filters as they are coming from a legitimate Google service.

“The attackers utilized Google Calendar services, making the headers appear completely legitimate and indistinguishable from invitations sent by any typical Google Calendar user,” Check Point told BleepingComputer.

The researchers shared an image of the email headers, showing they passed DKIM, SPF, and DMARC email security checks, allowing the phishing invite to land in the targets’ inboxes.

Mail headers sent in Google Calendar spam
Mail headers sent in Google Calendar spam
Source: Check Point

To double the number of phishing emails sent to the target, the threat actors can also cancel the Google Calendar event and include a message that will be sent to attendees.

This message can also include a link, such as a Google Drawings link, to further drive targets to phishing pages.

Using Google Drawings as part of Google Calendar phishing
Using Google Drawings as part of Google Calendar phishing
Source: Check Point

Google Calendar phishing is not new, with Google previously rolling out protections allowing users to block these types of invites more easily.

However, if a Google Workspace administrator does not enable these protections, you will continue to have invites automatically added to your calendars.

Check Point recommends that users be wary of all meeting invites received, and if they prompt you to click on a link, ignore them unless you trust or confirm the sender.

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
10:24 pm, Juni 19, 2025
Wetter-Symbol 22°C
L: 21° | H: 24°
aufgelockerte Bewölkung
Luftfeuchtigkeit: 62 %
Druck: 1025 mb
Wind: 11 mph E
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 34%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:42 am
Sonnenuntergang: 9:20 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Tomorrow 10:00 pm
Wetter-Symbol
21° | 24°°C 0 mm 0% 10 mph 71 % 1025 mb 0 mm/h
Sa. Juni 21 10:00 pm
Wetter-Symbol
18° | 32°°C 0 mm 0% 10 mph 60 % 1021 mb 0 mm/h
So. Juni 22 10:00 pm
Wetter-Symbol
19° | 26°°C 0.69 mm 69% 15 mph 76 % 1014 mb 0 mm/h
Mo. Juni 23 10:00 pm
Wetter-Symbol
16° | 23°°C 0.2 mm 20% 14 mph 78 % 1017 mb 0 mm/h
Di. Juni 24 10:00 pm
Wetter-Symbol
13° | 25°°C 0 mm 0% 13 mph 80 % 1017 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
18° | 21°°C 0 mm 0% 7 mph 65 % 1025 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
15° | 18°°C 0 mm 0% 6 mph 71 % 1024 mb 0 mm/h
Tomorrow 7:00 am
Wetter-Symbol
18° | 18°°C 0 mm 0% 6 mph 65 % 1024 mb 0 mm/h
Tomorrow 10:00 am
Wetter-Symbol
24° | 24°°C 0 mm 0% 8 mph 47 % 1024 mb 0 mm/h
Tomorrow 1:00 pm
Wetter-Symbol
27° | 27°°C 0 mm 0% 9 mph 35 % 1023 mb 0 mm/h
Tomorrow 4:00 pm
Wetter-Symbol
27° | 27°°C 0 mm 0% 10 mph 35 % 1023 mb 0 mm/h
Tomorrow 7:00 pm
Wetter-Symbol
25° | 25°°C 0 mm 0% 9 mph 41 % 1022 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
20° | 20°°C 0 mm 0% 7 mph 55 % 1022 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€90,909.12
-0.26%
Ethereum(ETH)
€2,185.66
-0.51%
Fesseln(USDT)
€0.87
-0.01%
XRP(XRP)
€1.88
-0.41%
Solana(SOL)
€126.85
-0.77%
USDC(USDC)
€0.87
-0.01%
Dogecoin(DOGE)
€0.147956
-0.38%
Shiba Inu(SHIB)
€0.000010
-1.49%
Pepe(PEPE)
€0.000009
-0.16%
Nach oben scrollen