Invitation-Themed Phishing Emails Deliver Malware and Steal Credentials

Summary
Cofense reports a sustained rise in invitation-themed phishing since early 2025. Campaigns spoof event services to steal credentials or deliver remote-access tools, with some links choosing a payload based on the recipient’s device.
Key points
- Cofense says invitation-themed emails account for nearly 15% of malware campaigns and just over 3% of credential-phishing campaigns it observed.
- Campaigns spoof services including Punchbowl, Greenvelope, Paperless Post and Evite, using polished invitations and emotional lures.
- Malware examples include ConnectWise RAT and Datto RMM, legitimate remote-access tools abused to control victims’ machines.
- Some malicious links detect the recipient’s device, delivering remote-access malware to computers and credential-phishing pages to mobile users.
- Cofense recommends employee awareness training, enforcing allowlists for remote-access tools, checking sender-domain and brand mismatches, and using password managers.
Article Details
- Attack Vectors
- Invitation-themed phishing emails spoof Punchbowl, Greenvelope, Paperless Post, and Evite to persuade recipients to click embedded links.
- Some invitation links lead to a page with a further link that downloads remote access software, including ConnectWise RAT or Datto RMM.
- Other links lead to credential-harvesting pages, including an AI-generated landing page and a page spoofing Google login.
- In one observed example, a link checks the recipient's device and delivers ConnectWise RAT to Windows users while redirecting mobile users to a credential-phishing page. The article also describes device detection used to deliver different remote access malware to Windows and MacOS machines.
- Defensive Notes
- Update employee awareness training and phishing simulations to use current lures; polished branding and error-free text are not reliable signs of legitimacy.
- Block malicious domains, enforce multi-factor authentication, and alert on suspicious attachments.
- Allowlist approved remote access tools and block unapproved tools from corporate devices; where an allowlist is unavailable, consider blocking certificates associated with unused remote access tools.
- Flag email when its sending domain does not match the displayed brand.
- Deploy enterprise password managers, which may decline to fill credentials on a domain that does not match the legitimate service.
- Provide an easy way for employees to report suspicious emails so security teams can investigate and remove them.
MITRE ATT&CK
T1204.001 · Malicious LinkThe lures rely on recipients clicking an invitation link to reach a phishing page or a page offering a malware download.T1566.002 · Spearphishing LinkInvitation-themed phishing emails contain links to credential-harvesting pages or remote access software downloads.T1598.003 · Spearphishing LinkInvitation-themed emails direct recipients through embedded links to pages intended to collect usernames and passwords.
Vendors
Cofenseparty invitation-themed emails to steal credentials and install malware on victims’ machines. Cofense Intelligence has observed a sustained rise in phishing campaigns disguised as event invitations, spoofingScreenConnectRAT. ConnectWise RAT is an abused, technically legitimate, remote access tool (RAT) published by ScreenConnect that is used to take control over the victim’s machine. Because ConnectWise RAT is also a legitimate
Products
Eviteas event invitations, spoofing trusted platforms such as Punchbowl, Greenvelope, Paperless Post, and Evite. Behind the familiar branding, these emails deliver credential-harvesting login pages and remote accessGreenvelopein phishing campaigns disguised as event invitations, spoofing trusted platforms such as Punchbowl, Greenvelope, Paperless Post, and Evite. Behind the familiar branding, these emails deliver credential-harvestingmacOSembedding device-detection logic that delivers different remote access malware to Windows machines and MacOS machines, as well as credential phishing pages for mobile devices, all from the same URL. This triples thePaperless Postcampaigns disguised as event invitations, spoofing trusted platforms such as Punchbowl, Greenvelope, Paperless Post, and Evite. Behind the familiar branding, these emails deliver credential-harvesting login pages andPunchbowlsustained rise in phishing campaigns disguised as event invitations, spoofing trusted platforms such as Punchbowl, Greenvelope, Paperless Post, and Evite. Behind the familiar branding, these emails deliverThreatHQsystem. At Cofense Intelligence, we maintain a database of Active Threat Reports (ATR) within our ThreatHQ platform. These ATRs detail different threat types seen by our Intelligence Analysts, such as CredentialWindowsThreat actors are embedding device-detection logic that delivers different remote access malware to Windows machines and MacOS machines, as well as credential phishing pages for mobile devices, all from the same
Tools
Aterafor remote access tools. Any remote access tool not on that list, including ConnectWise, SimpleHelp, Atera, and GoTo RAT, should be blocked from installing on corporate devices. Organizations that do not have anConnectWise RATpage. The brand spoofing is used alongside a compelling subject line and event name to deliver ConnectWise RAT. ConnectWise RAT is an abused, technically legitimate, remote access tool (RAT) published byDatto RMMfrom a family member without hesitation. Once the user clicks on this email, the email delivers Datto RMM, another abused RAT.GoTo RATaccess tools. Any remote access tool not on that list, including ConnectWise, SimpleHelp, Atera, and GoTo RAT, should be blocked from installing on corporate devices. Organizations that do not have an allowlistSimpleHelpallowlist for remote access tools. Any remote access tool not on that list, including ConnectWise, SimpleHelp, Atera, and GoTo RAT, should be blocked from installing on corporate devices. Organizations that do notTriageBusinesses can use tools and software provided by Cofense, such as Triage and Vision, to prevent initial access and future attacks. Triage allows for an in-depth breakdown of the phishing email, making it easier toVisionBusinesses can use tools and software provided by Cofense, such as Triage and Vision, to prevent initial access and future attacks. Triage allows for an in-depth breakdown of the phishing email, making it easier to