{"id":16384,"date":"2025-09-08T09:38:24","date_gmt":"2025-09-08T09:38:24","guid":{"rendered":"http:\/\/localhost\/?p=16384"},"modified":"2025-09-08T09:38:24","modified_gmt":"2025-09-08T09:38:24","slug":"icloud-calendar-infrastructure-abused-in-paypal-phishing-campaign","status":"publish","type":"post","link":"https:\/\/zero.redgem.net\/?p=16384","title":{"rendered":"iCloud Calendar infrastructure abused in PayPal phishing campaign_MALWAREBYTES:19BD76B9C9DCE9B7975F7B730AE5BDF1"},"content":{"rendered":"<p>{&#8220;lastseen&#8221;:&#8221;2025-09-08T14:05:27&#8243;,&#8221;description&#8221;:&#8221;Once again, phishers are targeting PayPal users by abusing existing legitimate infrastructure. Only this time they\u2019re not abusing PayPal\u2019s platform, but iCloud Calendar invites.\\n\\nOur friends over at BleepingComputer unraveled a call-back phishing scam which was sent to one of their readers.\\n\\n![Purchase invoice](https:\/\/www.malwarebytes.com\/wp-content\/uploads\/sites\/2\/2025\/09\/Calendar_invite.png)\\n\\n\\u003e \u201cPedro McCarthy invited you to \u2018Purchase Invoice\u2019.\\n\\u003e \\n\\u003e Purchase Invoice\\n\\u003e \\n\\u003e Hello Customer,  \\n\\u003e Your PayPal account has been billed $599.00  \\n\\u003e We\u2019re confirming receipt of your recent payment. Below are the details:  \\n\\u003e Invoice ID: AFER13VD\\n\\u003e \\n\\u003e Date: AUG 28, 2025\\n\\u003e \\n\\u003e Amount: USD 599.00\\n\\u003e \\n\\u003e If you wish to discuss or make changes to this payment, please contact our support team at +1 +1 (786) 902 8579\u201d\\n\\nThe sender email address shows as `noreply@email.apple.com` which helps it pass every imaginable email security check since it actually came from an Apple server. This happens because it is an iCloud Calendar invite, with the phishing text written in the \u201cNotes\u201d field.\\n\\nTo the recipient it shows a Microsoft 365 account controlled by the phishers. When creating such an iCloud Calendar event with external people added to the invite, an email is sent from Apple&#8217;s servers from the iCloud Calendar owner&#8217;s name with the email address `noreply@email.apple.com`.\\n\\nThe Microsoft 365 account is very likely a mailing list holding the email addresses of the targets in this campaign. This method allows the phishers to use the Microsoft Sender Rewriting Scheme (SRS), a technical method used to make email forwarding work smoothly without breaking anti-spoofing protections.\\n\\nBecause the rewritten sender address now belongs to the forwarding domain (e.g., Microsoft 365) it doesn\u2019t trigger any alarms. Meanwhile, the \\&#8221;From\\&#8221; address you see in your email program remains the same as the original sender, so the email looks legitimate to the recipient\u2014especially when that address belongs to Apple.\\n\\nA call-back phishing campaign is usually set up to entrap targets that decide to call the number listed in the invitation. They\u2019ll be asked to download something under false pretences, which often turns out to be a remote desktop client or information-stealing malware\u2014which will then be used to drain all your accounts.\\n\\n## How to stay safe\\n\\nDon\u2019t be fooled by the legitimate sender email address. Besides spoofing a sender email address, criminals are finding other ways to abuse big tech infrastructure and make it look as if an email came from a legitimate company.\\n\\nThe email has many of the usual signs of a phishing mail:\\n\\n  * Urgency is imposed by a large amount being billed\\n  * Generic greetings: \u201cHello customer\u201d and not your name.\\n  * The receiver\u2019s email address is not yours.\\n  * The spelling error in the phone number (twice the +1)\\n\\n\\n\\nWhat you can do:\\n\\n  * Always search phone numbers and email addresses to look for associations with known scams.\\n  * Login directly to PayPal.com to see if there are any messages in your account.\\n  * Enable two-factor authentication (2FA) on your Paypal account to add an extra layer of security to your financial accounts and help prevent scammers getting in.\\n  * Report suspicious emails and phishing emails to phishing@paypal.com. Then delete them.\\n\\n\\n\\n* * *\\n\\n**We don &#8216;t just report on scams\u2014we help detect them**\\n\\nCybersecurity risks should never spread beyond a headline. If something looks dodgy to you, check if it&#8217;s a scam using Malwarebytes Scam Guard, a feature of our mobile protection products. Submit a screenshot, paste suspicious content, or share a text or phone number, and we\u2019ll tell you if it&#8217;s a scam or legit. Download Malwarebytes Mobile Security for iOS or Android and try it today!&#8221;,&#8221;published&#8221;:&#8221;2025-09-08T12:47:47&#8243;,&#8221;modified&#8221;:&#8221;2025-09-08T12:47:47&#8243;,&#8221;type&#8221;:&#8221;malwarebytes&#8221;,&#8221;title&#8221;:&#8221;iCloud Calendar infrastructure abused in PayPal phishing campaign&#8221;,&#8221;source&#8221;:&#8221;&#8221;,&#8221;references&#8221;:&#8221;&#8221;,&#8221;id&#8221;:&#8221;MALWAREBYTES:19BD76B9C9DCE9B7975F7B730AE5BDF1&#8243;,&#8221;bulletinFamily&#8221;:&#8221;blog&#8221;,&#8221;cwe&#8221;:null,&#8221;cvelist&#8221;:[],&#8221;sourceData&#8221;:&#8221;&#8221;,&#8221;sourceHref&#8221;:&#8221;&#8221;,&#8221;cvss&#8221;:{&#8220;score&#8221;:0,&#8221;severity&#8221;:&#8221;NONE&#8221;,&#8221;vector&#8221;:&#8221;NONE&#8221;,&#8221;version&#8221;:&#8221;NONE&#8221;},&#8221;cvss2&#8243;:{},&#8221;cvss3&#8243;:{&#8220;version&#8221;:&#8221;&#8221;,&#8221;vectorString&#8221;:&#8221;&#8221;,&#8221;baseScore&#8221;:0,&#8221;baseSeverity&#8221;:&#8221;&#8221;,&#8221;attackVector&#8221;:&#8221;&#8221;,&#8221;attackComplexity&#8221;:&#8221;&#8221;,&#8221;privilegesRequired&#8221;:&#8221;&#8221;,&#8221;userInteraction&#8221;:&#8221;&#8221;,&#8221;scope&#8221;:&#8221;&#8221;,&#8221;confidentialityImpact&#8221;:&#8221;&#8221;,&#8221;integrityImpact&#8221;:&#8221;&#8221;,&#8221;availabilityImpact&#8221;:&#8221;&#8221;,&#8221;cvssV3&#8243;:{&#8220;version&#8221;:&#8221;&#8221;,&#8221;vectorString&#8221;:&#8221;&#8221;,&#8221;baseScore&#8221;:0,&#8221;baseSeverity&#8221;:&#8221;&#8221;,&#8221;attackVector&#8221;:&#8221;&#8221;,&#8221;attackComplexity&#8221;:&#8221;&#8221;,&#8221;privilegesRequired&#8221;:&#8221;&#8221;,&#8221;userInteraction&#8221;:&#8221;&#8221;,&#8221;scope&#8221;:&#8221;&#8221;,&#8221;confidentialityImpact&#8221;:&#8221;&#8221;,&#8221;integrityImpact&#8221;:&#8221;&#8221;,&#8221;availabilityImpact&#8221;:&#8221;&#8221;}},&#8221;href&#8221;:&#8221;https:\/\/www.malwarebytes.com\/blog\/news\/2025\/09\/icloud-calendar-infrastructure-abused-in-paypal-phishing-campaign&#8221;,&#8221;category_name&#8221;:&#8221;News&#8221;,&#8221;post_link&#8221;:&#8221;&#8221;,&#8221;product&#8221;:&#8221;&#8221;,&#8221;version&#8221;:&#8221;&#8221;,&#8221;vendor&#8221;:&#8221;&#8221;,&#8221;ai_description&#8221;:&#8221;&#8221;,&#8221;ai_severity&#8221;:&#8221;&#8221;,&#8221;ai_vendor&#8221;:&#8221;&#8221;,&#8221;ai_product&#8221;:&#8221;&#8221;,&#8221;ai_version&#8221;:&#8221;&#8221;,&#8221;ai_score&#8221;:0}<\/p>\n","protected":false},"excerpt":{"rendered":"<p>{&#8220;lastseen&#8221;:&#8221;2025-09-08T14:05:27&#8243;,&#8221;description&#8221;:&#8221;Once again, phishers are targeting PayPal users by abusing existing legitimate infrastructure. Only this time they\u2019re not abusing PayPal\u2019s platform, but iCloud Calendar invites.\\n\\nOur friends&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[6,8,12,115,13,33,7,11,5],"class_list":["post-16384","post","type-post","status-publish","format-standard","hentry","category-category_news","tag-cve","tag-cvss","tag-exploit","tag-malwarebytes","tag-news","tag-none","tag-security","tag-tapic","tag-vulnerability"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>iCloud Calendar infrastructure abused in PayPal phishing campaign_MALWAREBYTES:19BD76B9C9DCE9B7975F7B730AE5BDF1 - zero redgem<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/zero.redgem.net\/?p=16384\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"iCloud Calendar infrastructure abused in PayPal phishing campaign_MALWAREBYTES:19BD76B9C9DCE9B7975F7B730AE5BDF1 - zero redgem\" \/>\n<meta property=\"og:description\" content=\"{&#8220;lastseen&#8221;:&#8221;2025-09-08T14:05:27&#8243;,&#8221;description&#8221;:&#8221;Once again, phishers are targeting PayPal users by abusing existing legitimate infrastructure. Only this time they\u2019re not abusing PayPal\u2019s platform, but iCloud Calendar invites.nnOur friends...\" \/>\n<meta property=\"og:url\" content=\"https:\/\/zero.redgem.net\/?p=16384\" \/>\n<meta property=\"og:site_name\" content=\"zero redgem\" \/>\n<meta property=\"article:published_time\" content=\"2025-09-08T09:38:24+00:00\" \/>\n<meta name=\"author\" content=\"invoker\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"invoker\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=16384#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=16384\"},\"author\":{\"name\":\"invoker\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\"},\"headline\":\"iCloud Calendar infrastructure abused in PayPal phishing campaign_MALWAREBYTES:19BD76B9C9DCE9B7975F7B730AE5BDF1\",\"datePublished\":\"2025-09-08T09:38:24+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=16384\"},\"wordCount\":795,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"keywords\":[\"CVE\",\"CVSS\",\"exploit\",\"malwarebytes\",\"news\",\"NONE\",\"Security\",\"tapic\",\"Vulnerability\"],\"articleSection\":[\"category_news\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=16384#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=16384\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?p=16384\",\"name\":\"iCloud Calendar infrastructure abused in PayPal phishing campaign_MALWAREBYTES:19BD76B9C9DCE9B7975F7B730AE5BDF1 - zero redgem\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\"},\"datePublished\":\"2025-09-08T09:38:24+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=16384#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=16384\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=16384#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/zero.redgem.net\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"iCloud Calendar infrastructure abused in PayPal phishing campaign_MALWAREBYTES:19BD76B9C9DCE9B7975F7B730AE5BDF1\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"name\":\"zero redgem\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/zero.redgem.net\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\",\"name\":\"zero redgem\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"\",\"contentUrl\":\"\",\"width\":191,\"height\":188,\"caption\":\"zero redgem\"},\"image\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\",\"name\":\"invoker\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"caption\":\"invoker\"},\"sameAs\":[\"https:\\\/\\\/zero.redgem.net\"],\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?author=1\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"iCloud Calendar infrastructure abused in PayPal phishing campaign_MALWAREBYTES:19BD76B9C9DCE9B7975F7B730AE5BDF1 - zero redgem","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/zero.redgem.net\/?p=16384","og_locale":"en_US","og_type":"article","og_title":"iCloud Calendar infrastructure abused in PayPal phishing campaign_MALWAREBYTES:19BD76B9C9DCE9B7975F7B730AE5BDF1 - zero redgem","og_description":"{&#8220;lastseen&#8221;:&#8221;2025-09-08T14:05:27&#8243;,&#8221;description&#8221;:&#8221;Once again, phishers are targeting PayPal users by abusing existing legitimate infrastructure. Only this time they\u2019re not abusing PayPal\u2019s platform, but iCloud Calendar invites.nnOur friends...","og_url":"https:\/\/zero.redgem.net\/?p=16384","og_site_name":"zero redgem","article_published_time":"2025-09-08T09:38:24+00:00","author":"invoker","twitter_card":"summary_large_image","twitter_misc":{"Written by":"invoker","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/zero.redgem.net\/?p=16384#article","isPartOf":{"@id":"https:\/\/zero.redgem.net\/?p=16384"},"author":{"name":"invoker","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca"},"headline":"iCloud Calendar infrastructure abused in PayPal phishing campaign_MALWAREBYTES:19BD76B9C9DCE9B7975F7B730AE5BDF1","datePublished":"2025-09-08T09:38:24+00:00","mainEntityOfPage":{"@id":"https:\/\/zero.redgem.net\/?p=16384"},"wordCount":795,"commentCount":0,"publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"keywords":["CVE","CVSS","exploit","malwarebytes","news","NONE","Security","tapic","Vulnerability"],"articleSection":["category_news"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/zero.redgem.net\/?p=16384#respond"]}]},{"@type":"WebPage","@id":"https:\/\/zero.redgem.net\/?p=16384","url":"https:\/\/zero.redgem.net\/?p=16384","name":"iCloud Calendar infrastructure abused in PayPal phishing campaign_MALWAREBYTES:19BD76B9C9DCE9B7975F7B730AE5BDF1 - zero redgem","isPartOf":{"@id":"https:\/\/zero.redgem.net\/#website"},"datePublished":"2025-09-08T09:38:24+00:00","breadcrumb":{"@id":"https:\/\/zero.redgem.net\/?p=16384#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/zero.redgem.net\/?p=16384"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/zero.redgem.net\/?p=16384#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/zero.redgem.net\/"},{"@type":"ListItem","position":2,"name":"iCloud Calendar infrastructure abused in PayPal phishing campaign_MALWAREBYTES:19BD76B9C9DCE9B7975F7B730AE5BDF1"}]},{"@type":"WebSite","@id":"https:\/\/zero.redgem.net\/#website","url":"https:\/\/zero.redgem.net\/","name":"zero redgem","description":"","publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/zero.redgem.net\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/zero.redgem.net\/#organization","name":"zero redgem","url":"https:\/\/zero.redgem.net\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/","url":"","contentUrl":"","width":191,"height":188,"caption":"zero redgem"},"image":{"@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca","name":"invoker","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","caption":"invoker"},"sameAs":["https:\/\/zero.redgem.net"],"url":"https:\/\/zero.redgem.net\/?author=1"}]}},"_links":{"self":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/16384","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=16384"}],"version-history":[{"count":0,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/16384\/revisions"}],"wp:attachment":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=16384"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=16384"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=16384"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}