started · updated
Cybersecurity alerts warn of calendar phishing and malicious mobile apps
Cybersecurity experts are warning users about two distinct methods used by hackers to steal personal data and financial information.
One method involves suspicious calendar invitations. Attackers exploit the ICS file format used by Google Calendar, Microsoft Outlook, and Apple Calendar to automatically insert mysterious meetings into a user's schedule. These invitations often contain malicious links that lead to phishing sites or malware installation. Cybersecurity firm Sublime has noted an increase in these attacks, which frequently use free email accounts to bypass security systems. Experts recommend deleting unknown invites immediately without accepting or declining them to avoid confirming the email address is active.
Another threat involves malicious mobile applications, particularly those distributed via APK files outside of official app stores. Scammers often disguise these apps as free tools for watching sports or encrypted channels. Once installed, these apps may request excessive permissions, such as accessibility services or screen control, allowing them to monitor user activity. This poses a specific risk to banking applications like InstaPay, as malware can observe or interfere with transactions while the user is interacting with their device.
Entities
Apple Calendar · Google Calendar · InstaPay · Microsoft Outlook · Sublime