Invitation-Themed Phishing Emails Deliver Malware and Steal Credentials

· Original article ↗

Summary

Cofense reports a sustained rise in invitation-themed phishing since early 2025. Campaigns spoof event services to steal credentials or deliver remote-access tools, with some links choosing a payload based on the recipient’s device.

Key points

  • Cofense says invitation-themed emails account for nearly 15% of malware campaigns and just over 3% of credential-phishing campaigns it observed.
  • Campaigns spoof services including Punchbowl, Greenvelope, Paperless Post and Evite, using polished invitations and emotional lures.
  • Malware examples include ConnectWise RAT and Datto RMM, legitimate remote-access tools abused to control victims’ machines.
  • Some malicious links detect the recipient’s device, delivering remote-access malware to computers and credential-phishing pages to mobile users.
  • Cofense recommends employee awareness training, enforcing allowlists for remote-access tools, checking sender-domain and brand mismatches, and using password managers.

Article Details

Attack Vectors
  • Invitation-themed phishing emails spoof Punchbowl, Greenvelope, Paperless Post, and Evite to persuade recipients to click embedded links.
  • Some invitation links lead to a page with a further link that downloads remote access software, including ConnectWise RAT or Datto RMM.
  • Other links lead to credential-harvesting pages, including an AI-generated landing page and a page spoofing Google login.
  • In one observed example, a link checks the recipient's device and delivers ConnectWise RAT to Windows users while redirecting mobile users to a credential-phishing page. The article also describes device detection used to deliver different remote access malware to Windows and MacOS machines.
Defensive Notes
  • Update employee awareness training and phishing simulations to use current lures; polished branding and error-free text are not reliable signs of legitimacy.
  • Block malicious domains, enforce multi-factor authentication, and alert on suspicious attachments.
  • Allowlist approved remote access tools and block unapproved tools from corporate devices; where an allowlist is unavailable, consider blocking certificates associated with unused remote access tools.
  • Flag email when its sending domain does not match the displayed brand.
  • Deploy enterprise password managers, which may decline to fill credentials on a domain that does not match the legitimate service.
  • Provide an easy way for employees to report suspicious emails so security teams can investigate and remove them.

MITRE ATT&CK

Vendors

Products

Eviteas event invitations, spoofing trusted platforms such as Punchbowl, Greenvelope, Paperless Post, and Evite. Behind the familiar branding, these emails deliver credential-harvesting login pages and remote accessGreenvelopein phishing campaigns disguised as event invitations, spoofing trusted platforms such as Punchbowl, Greenvelope, Paperless Post, and Evite. Behind the familiar branding, these emails deliver credential-harvestingmacOSembedding device-detection logic that delivers different remote access malware to Windows machines and MacOS machines, as well as credential phishing pages for mobile devices, all from the same URL. This triples thePaperless Postcampaigns disguised as event invitations, spoofing trusted platforms such as Punchbowl, Greenvelope, Paperless Post, and Evite. Behind the familiar branding, these emails deliver credential-harvesting login pages andPunchbowlsustained rise in phishing campaigns disguised as event invitations, spoofing trusted platforms such as Punchbowl, Greenvelope, Paperless Post, and Evite. Behind the familiar branding, these emails deliverThreatHQsystem. At Cofense Intelligence, we maintain a database of Active Threat Reports (ATR) within our ThreatHQ platform. These ATRs detail different threat types seen by our Intelligence Analysts, such as CredentialWindowsThreat actors are embedding device-detection logic that delivers different remote access malware to Windows machines and MacOS machines, as well as credential phishing pages for mobile devices, all from the same

Tools

Related Articles