The Sudden Surge in ICS Phishing
Security analysts at Sublime have issued a stark warning regarding the rapid escalation of phishing attacks utilizing ICS (Internet Calendar) files. According to their latest findings, this specific attack vector has seen an explosive growth rate of approximately 33,000% between May and September 2026. Experts suggest that this method has moved from a niche technique into the mainstream arsenal of cybercriminals.
How the Attack Works
The success of this phishing strategy lies in its simplicity and the inherent trust users place in calendar notifications. By leveraging legitimate services like Gmail to distribute invites, attackers effectively circumvent most standard email security protocols. Because the infrastructure used to send these requests is reputable, they often bypass spam filters entirely.
The victim is targeted twice: first through an email notification and again via an entry in their calendar application. The core of the threat usually involves a link embedded within the calendar invite, which directs the user to download a remote monitoring and management (RMM) tool, such as ScreenConnect. Once installed, these tools grant attackers unauthorized control over the device, allowing them to:
- Deploy secondary malware, including ransomware or information-stealing software.
- Harvest sensitive documentation and login credentials.
- Establish a persistent foothold for long-term espionage.
Rapid Growth and Escalation
Data provided by Sublime highlights an aggressive upward trend. While the technique began to gain traction roughly a year ago, the frequency of these attacks has surged dramatically in recent months:
- May to June: 282% increase.
- June to July: 338% increase.
- July to August: 1,216% increase.
- Mid-September estimates: 1,426% increase compared to all of August.
«The jumps in August and September appear to be indicators that this attack type has finally hit the mainstream,» the researchers noted in their report.
How to Protect Your Accounts
Defending against ICS-based threats requires a proactive approach. Users are encouraged to scrutinize every calendar invite with skepticism. Key red flags include:
- Unexpected event invites from unknown or suspicious senders.
- High-pressure or urgent language related to financial matters.
- Suspicious links or calls-to-action (CTA) inside the event description.
Always verify the sender's identity before interacting with any attachments or links contained within calendar notifications.
