Slow Fog: Hackers Insert Malicious Links in Calendar App Calendly to Launch Phishing Attacks
ChainCatcher message, the Slow Mist Security Team has discovered that hacker organizations are using Calendly's features to insert malicious links on event pages via the "Add Custom Link" function to initiate phishing attacks.Calendly is a very popular free calendar application used for scheduling meetings and appointments, often utilized by organizations to book events or send invitations for upcoming activities. Hacker organizations send malicious links through Calendly, which blend well with the daily work context of most victims, making these malicious links less likely to raise suspicion. Victims may inadvertently click on the malicious links, unknowingly downloading and executing malicious code, resulting in losses.The Slow Mist Security Team reminds everyone that when using Calendly, if you see links on the interface, please be cautious in identifying the source and domain of the links to avoid falling victim to attacks. You can hover your mouse over the text before clicking the link; at this point, the corresponding link address will be displayed in the lower left corner of the browser. Please carefully verify the link address before clicking to avoid accessing phishing links.