How Attackers Used ICloud Calendar To Send Phishing Emails From Apple

A new phishing campaign is abusing Apple’s iCloud Calendar invitation system to push malicious links. Because these invites are delivered directly from Apple’s own email servers, they easily slip past most email defenses and land straight in user inboxes

The attackers are banking on the trust people place in Apple’s brand. Calendar invites appear to come from legitimate Apple domains, but the Notes section is weaponized with phishing links

In multiple cases, the links redirected to fake Microsoft 365 login pages designed to steal credentials. Since the delivery is routed through Apple, the invites not only look authentic but also generate notifications across services like Microsoft Teams—making them even harder to dismiss as suspicious

Invitation Functionality: How the Abuse Works

Apple’s calendar service lets users send event invitations to outside contacts. By default, Apple sends these emails through noreply@email.apple.com on the user’s behalf. Attackers are now exploiting this feature by planting phishing URLs in the Notes field. Because the messages come from Apple’s infrastructure, spam filters and secure email gateways rarely flag them

Technical Breakdown of the Campaign

1. Invitation Email Example

The calendar invitation is styled as a normal meeting event with a title such as “CSI Team – WizardCyber” and includes a link in the Notes section:

Notes:

Login to reserve your appointment

URL: http://[malicious-domain]/login

2. Cross-Platform Notification Abuse

Since the invites are trusted and authenticated, they don’t just arrive in the inbox—they also trigger alerts in linked platforms like Microsoft Teams. This increases the reach and makes the malicious content appear legitimate across multiple channels

Why Does It Pass Email Protection Solutions?

High Authentication Success Rate

The phishing messages successfully pass SPF, DKIM, and DMARC checks, which makes them appear authentic to both users and automated email security systems.

Since the emails are sent from a highly trusted domain (apple.com), the authentication results are:

 

SPF: pass (sender IP authorized)

DKIM: pass (signature matches)

DMARC: pass (domain alignment validated)

Sender IP: 17.111.10.43

From: noreply@email.apple.com

Uncommon Attack Vector

Calendar invitations are not typically associated with phishing, so users may not be as vigilant. Furthermore, the Notes section is often overlooked by email security scanners, making it an attractive location for embedding phishing content.

How Wizard Cyber Defends Against this Threat

As a Microsoft Partner and MSSP, Wizard Cyber helps organizations close gaps that traditional email defenses miss. We combine threat intelligence with proactive monitoring to stop phishing campaigns like this before they compromise accounts

Our services include:

Our global SOC team monitors activity around the clock, hunts for signs of compromise, and strengthens identity and access security to keep your business safe

CYBERSECURITY READINESS

Strengthen Your Cyber Defences Today

As cyber threats grow more complex, proactive detection is no longer optional.

With Wizard Cyber’s Microsoft expertise, organizations can transform their security posture and gain real-time visibility across all endpoints.

Start your journey to smarter, faster cybersecurity today.

EXPLORE MORE

Related Blogs & Insights

Discover blogs that deepen your knowledge and accelerate your security strategy.

ABOUT THE AUTHOR
Mahdi Alabdallah
Offensive Security Engineer

Mahdi specialises in penetration testing, web application security, network security assessments, and vulnerability exploitation. He holds the globally recognised OSCP (Offensive Security Certified Professional) certification, eCPPT, eWPT, and eCIR certifications, alongside Microsoft SC-200, SC-300, and AZ-500 certifications

 

Certifications: OSCP+/OSCP, eCPPT, eWPT, eCIR, SC200, SC300, AZ500

Cyber Shield Intelligence (CSI) Team

Cyber Shield Intelligence (CSI) Team

Wizard Cyber’s first line of defense in proactive threat intelligence. CSI is dedicated to the identification, monitoring, and analysis of emerging cyber threats, including activity across the dark web, underground forums, and threat actor infrastructure. Leveraging advanced threat intelligence platforms, OSINT tools, and adversary tracking methodologies, the team provides actionable intelligence to anticipate attacks before they occur. With expertise in threat actor profiling, TTP mapping (aligned with the MITRE ATT&CK framework), and IOC enrichment, CSI equips clients with the critical insights needed to fortify defenses, mitigate risk, and stay ahead of evolving threat landscapes.

WIZARD CYBER
Headquarters
Providing enterprises with bespoke & powerful managed solutions to protect against all forms of cybercrime
OUR LOCATIONS
Where to find us?
world map
GET IN TOUCH
Latest Updates
Stay up to date with the latest news from Wizard Cyber and the cybersecurity industry
https://wizardcyber.com/wp-content/uploads/2026/04/ISO-QSL-Cert-ISO-27001-scaled.png
https://wizardcyber.com/wp-content/uploads/2026/04/ISO-QSL-Cert-ISO-9001-scaled.png
WIZARD CYBER
Headquarters
Providing enterprises with bespoke & powerful managed solutions to protect against all forms of cybercrime
OUR LOCATIONS
Where to find us?
world map
GET IN TOUCH
Latest Updates
Stay up to date with the latest news from Wizard Cyber and the cybersecurity industry

Copyright by Wizard Cyber. All rights reserved.

Copyright by Wizard Cyber. All rights reserved.

Contact Us
×
Contact Us
Need Cybersecurity Guidance? Get in touch with us!

Our experts are ready to help with your cybersecurity questions—book a conversation with us by clicking the button.

Book a Meeting
Funded Workshops
×
Funded Workshops
Explore Our Funded Microsoft Security Workshops

Click to learn more about each Microsoft-supported engagement

Book a Consultation