PULSE NAME
The Hidden Dangers of Calendar Subscriptions: 4 Million Devices at Risk
WHITE AlienVault 2025-11-26 Modified: 2025-11-26
23
IOCs
MEDIUM VOLUME
Bitsight researchers uncovered a significant security risk associated with calendar subscriptions, potentially affecting 4 million devices. Expired or hijacked domains hosting calendar subscriptions can be exploited for large-scale social engineering attacks. The research revealed two types of sync requests reaching their sinkhole, indicating different networks at play. The infrastructure behind these operations was found to be deliberate and planned, with domains actively registered until 2025. The attack vector leverages users' trust in calendar events, making it more effective than traditional phishing emails. The researchers also discovered links to the Balada injector campaign, involving website compromises and redirection chains. The scale of operations includes over 1,300 domains and various monetization strategies, including selling calendar event ad space.
Indicators of Compromise (23)
All CVE FileHash-SHA256 URL domain hostname
TYPEINDICATORDESCRIPTIONCREATED
CVE CVE-2025-27915 2025-11-26
FileHash-SHA256 e05c546f30212173ba878c31bbd8b93216cab1e847676b7bae870719f37dd7a5 2025-11-26
URL http://1downloadss0ftware.xyz/gogo/gotb/ 2025-11-26
URL http://linetoslice.com/scripts 2025-11-26
URL http://mos3.biz/?webcal=me2tanrymi5gi3bpgu4tmna&u=230c9837-23ee-4208-8df0-1fa854490c90&l=24&t=1620652575&g=3&al=ar&sub1=&sub2=&sub3=&sub4=b0690ftho9zwh124 2025-11-26
URL http://perfectlinestarter.com/scripts 2025-11-26
URL https://mo17.biz/?p=gy3ggyrzgm5gi3bpgy2dsny 2025-11-26
URL https://mo17.biz/?webcal=me2tanrymi5gi3bpgu4tmna&u=230c9837-23ee-4208-8df0-1fa854490c90&l=24&t=1620652575&g=3&al=ar&sub1=&sub2=&sub3=&sub4=b0690ftho9zwh124 2025-11-26
domain 1downloadss0ftware.xyz 2025-11-26
domain bestresulttostart.com 2025-11-26
domain deobfuscate.io 2025-11-26
domain linetoslice.com 2025-11-26
domain linetowaystrue.com 2025-11-26
domain mo17.biz 2025-11-26
domain mos3.biz 2025-11-26
domain perfectlinestarter.com 2025-11-26
domain readytocheckline.com 2025-11-26
domain recordsbluemountain.com 2025-11-26
domain taskscompletedlists.com 2025-11-26
domain topwebsites1d.com 2025-11-26
hostname 0.allowandgo.com 2025-11-26
hostname 0.blueandbesthome.com 2025-11-26
hostname 0.mo12.biz 2025-11-26