The Hidden Dangers of Calendar Subscriptions: 4 Million Devices at Risk

Nov. 26, 2025, 10:51 a.m.

Description

Bitsight researchers uncovered a significant security risk associated with calendar subscriptions, potentially affecting 4 million devices. Expired or hijacked domains hosting calendar subscriptions can be exploited for large-scale social engineering attacks. The research revealed two types of sync requests reaching their sinkhole, indicating different networks at play. The infrastructure behind these operations was found to be deliberate and planned, with domains actively registered until 2025. The attack vector leverages users' trust in calendar events, making it more effective than traditional phishing emails. The researchers also discovered links to the Balada injector campaign, involving website compromises and redirection chains. The scale of operations includes over 1,300 domains and various monetization strategies, including selling calendar event ad space.

Date

  • Created: Nov. 26, 2025, 9:27 a.m.
  • Published: Nov. 26, 2025, 9:27 a.m.
  • Modified: Nov. 26, 2025, 10:51 a.m.

Indicators

  • e05c546f30212173ba878c31bbd8b93216cab1e847676b7bae870719f37dd7a5
  • https://mo17.biz/?webcal=me2tanrymi5gi3bpgu4tmna&u=230c9837-23ee-4208-8df0-1fa854490c90&l=24&t=1620652575&g=3&al=ar&sub1=&sub2=&sub3=&sub4=b0690ftho9zwh124
  • https://mo17.biz/?p=gy3ggyrzgm5gi3bpgy2dsny
  • http://mos3.biz/?webcal=me2tanrymi5gi3bpgu4tmna&u=230c9837-23ee-4208-8df0-1fa854490c90&l=24&t=1620652575&g=3&al=ar&sub1=&sub2=&sub3=&sub4=b0690ftho9zwh124
  • http://perfectlinestarter.com/scripts
  • http://linetoslice.com/scripts
  • http://1downloadss0ftware.xyz/gogo/gotb/
  • 0.mo12.biz
  • 0.blueandbesthome.com
  • 0.allowandgo.com
  • topwebsites1d.com
  • taskscompletedlists.com
  • recordsbluemountain.com
  • readytocheckline.com
  • perfectlinestarter.com
  • mos3.biz
  • mo17.biz
  • linetowaystrue.com
  • linetoslice.com
  • bestresulttostart.com
  • 1downloadss0ftware.xyz
  • deobfuscate.io

Attack Patterns

Additional Informations

  • Technology
  • Education
  • Finance
  • Government
  • United States of America

Linked vulnerabilities