Hackers Using Calendly-Themed Phishing Attack to Steal Google Workspace Account
A recent phishing campaign has been identified, targeting business professionals with emails themed around Calendly. These emails use social engineering tactics combined with advanced credential theft techniques.
A recent phishing campaign has been identified, targeting business professionals with emails themed around Calendly. These emails use social engineering tactics combined with advanced credential theft techniques.
The campaign specifically targets Google Workspace and Facebook Business accounts by sending emails that appear to offer job opportunities, tricking recipients into disclosing their login credentials.
The phishing campaign was initiated when a customer received an email impersonating a recruiter from LVMH. This email praised the recipient's professional achievements and offered a job opportunity within LVMH's digital performance team. The email included personal details about the recipient's work experience and was signed by an individual claiming to be an HR manager.
Security analysts at Push Security discovered that the attack is part of a broader campaign involving multiple variants and brands. They noted the sophisticated social engineering tactics and detection evasion techniques embedded in the attack infrastructure.
A recent phishing campaign has been identified, targeting business professionals with emails themed around Calendly.
The phishing attack employs a multi-stage delivery method to bypass email security filters. Initially, the email inquires if the recipient is interested in the opportunity. Only after a response is received does the attacker send a follow-up email containing a malicious link disguised as a Calendly scheduling link. This approach helps evade content scanning tools that typically flag messages with suspicious links.
Upon clicking the link, victims are directed to a fake Calendly page resembling the legitimate service. After completing a CAPTCHA verification and clicking "Continue with Google," users are redirected to an Attacker-in-the-Middle (AiTM) phishing page. This page mimics Google's login interface but incorporates Calendly branding to appear authentic.
The phishing infrastructure includes validation mechanisms that restrict access to unauthorized email domains. Only emails from the intended victim's organization domain can proceed to the password entry field. Researchers also identified advanced anti-analysis features, such as IP blocking to prevent investigations from VPN or proxy connections and access restrictions when developer tools are opened.
The campaign has evolved significantly since its onset, with attackers continuously refining their tactics and introducing new detection evasion methods to maintain operational effectiveness.
Based on reporting by Cyber Security News.
