top | item 20807921

Google Calendar Event Injection with MailSniper (2017)

117 points| andrewaylett | 6 years ago |blackhillsinfosec.com

70 comments

order
[+] andrejus|6 years ago|reply
I've received a bunch of calendar invites for "Free i PhoneXs from AppleStore" with a malicious link. Seems like this is now being used for phishing attacks.

I believe API abuse can be reported -- https://support.google.com/code/contact/cloud_platform_repor...

[+] kop316|6 years ago|reply
I can confirm it's being actively exploited this morning (I had a few folks I know complain about it). I think I should point out that the article was written in 2017 (!!!), and Google responded that this is a "feature".

Thank you to OP!

[+] patch_collector|6 years ago|reply
I'd never received one of these until this morning, at about the same time I read this article. Now I just received the same one as you :P
[+] wastedhours|6 years ago|reply
I've been getting a lot more recently - seemingly being added from Gmail spam (either that or I'm getting directly injected calendar spam and the same as emails coming through). I don't want to turn off syncing as actual bookings being automatically added are useful.
[+] tabs_masterrace|6 years ago|reply
Got some too. What's super weird though, these calendar invites appear to have been sent from my iCloud email address to my gmail address, and also appear in the sent folder of my @me.com address: https://i.imgur.com/tz2TUh5.png

Anyone else can check in your gmail spam folder if you have those emails too and where they came from?

[+] chli|6 years ago|reply
Same happened to me last night, I reviewed all my access rights on security.google.com, couldn't find anything wrong. Reviewed my calendar access rights, couldn't find anything wrong.

Glad to have an explanation for this phenomenon.

[+] draxofavalon|6 years ago|reply
Same thing here, exact same ad, I reported it as spam.
[+] kburman|6 years ago|reply
Invites are set up as a recurring event, so make sure to delete all the events. You can do a search to find any leftover.
[+] faramarz|6 years ago|reply
I had to go into the Gmail UI to report the event as spam and seems to have fixed the issue for me.

in the process disabled the automatic fetching of events from my emails which was causing double bookings; ahh!

[+] macNchz|6 years ago|reply
I just got like 10 of these iPhone ones overnight.
[+] jolesf|6 years ago|reply
Got the same thing just yesterday.
[+] sethvargo|6 years ago|reply
Hey everyone - Seth here from Google. I'm sorry to hear this is happening. This post is from November 2017, and we've taken steps to reduce calendar spam. If you have specific invitations that came with an email, please forward the entire email to [email protected]. If it did not come with an email, please copy the calendar details and a screenshot into an email and send it to [email protected].

You can use this form for reporting mail/calendar abuse: https://support.google.com/mail/contact/abuse

[+] rcfox|6 years ago|reply
I've received a few myself and hit the spam button on the calendar events. I'd hope you are looking at that bucket too.
[+] 101008|6 years ago|reply
In the last weeks, I had several events on my Google Calendar that I did not create or accepted. They looked like they were in Russian, but I can't be sure. I marked as spam and deleted them, of course, but the next week a different one appeared. Anyone else is going through the same and have any advice?
[+] notusererror|6 years ago|reply
Same here, and I suspect this article explains the mechanism.

For weeks, I've been getting escalating numbers of events. It is up to 4 or 5 new invites per day, each with daily repeats. My calendar settings are locked down (eg "Events from Gmail" off) and already have 2FA on the account. Next step for me is to delete gmail calendar entirely.

I went to bed last night with a clean calendar, this morning I have 3 spam invites - 2 in Cyrillic alphabet, one "You have won iPhoneXs. Gotta love 3:55 AM wake-up alerts...

[+] MatekCopatek|6 years ago|reply
Had the same happen, searched around and it seemed to be caused by the Gmail feature that automatically creates events from invitation emails you receive, even if they land in spam. Spammers seemed to be using that to their advantage, so I just turned the feature off.

EDIT: The original article covers this and more, go read it :)

[+] blck|6 years ago|reply
I’ve had the exact same happen to me with calendar events a couple times.

I also got added to what looked like a Russian Hangouts group chat with over 100 people in it.

[+] superzadeh|6 years ago|reply
Same here, I had 3 recurring events about an iPhone X sale or some other spam come in my calendar in the past 2 weeks.
[+] ww520|6 years ago|reply
Got hit by this. Super annoying. It's not through email. It just showed up in calendar. There's no way to know the original scheduler and no way to mark it as spam.

There's a variant to this, the calendar event triggered by an event invitation. Again no way to delete it except decline the event. Should have a report spam button in the calendar app.

[+] erikerikson|6 years ago|reply
Agreed the app could use it. The report as spam capability is in the web version and works.
[+] sdoering|6 years ago|reply
Could someone please add [2017] to the title?

Not sure what happened in the nearly two years since this post went public. But at least we would now, that this is not a current disclosure.

[+] kop316|6 years ago|reply
There has been a fresh wave of folks exploiting it recently (I have had a few people complain in the past 12 hours about calendar spam). Google apparently stands by the fact that it is a "feature"
[+] sctb|6 years ago|reply
Added. Thanks!
[+] djake|6 years ago|reply
A Report SPAM button on calendar invites would seem to be in order, so I don't have to manually delete each of these from the same address, and so Google can ban the offending account quickly.

Edit: it appears you can do this on desktop but not mobile: https://support.google.com/calendar/answer/6110973?co=GENIE....

[+] serf|6 years ago|reply
>A Report SPAM button on calendar invites would seem to be in order

there is one, and it works exactly like that. A single spam report kills all of the events from that sender.

[+] RandomBacon|6 years ago|reply
The fact that we now need a spam button on our calender is ridiculous.

How long until advertisers pay <calendar provider> to add events to our calendars such as take Mom to <resturant> for Mother's Day, Watch <movie> on its release day, Go To <store> on its grand opening, etc?

(Please take this as a warning, not a "feature" suggestion.)

[+] hellogoodbye|6 years ago|reply
exactly, why on earth is there no "Report Spam" button on mobile?!
[+] icecap12|6 years ago|reply
Kudos to BHIS for the post and detail. I've been seeing these pop into my Google Calendar randomly for the past few weeks; obvious phishing attacks. You can easily delete them of course, but definitely an annoyance.
[+] Jonnax|6 years ago|reply
How are they not sending an email but putting stuff in my calendar?

When a friend sends me an invite on Google from their Gmail to my Gmail, I get an email.

I didn't think there was another mechanism.

[+] Jivatman|6 years ago|reply
Check your spam folder, I believe this technique works even if the email was sent to spam.
[+] NikolaeVarius|6 years ago|reply
I had a ad on my calendar yesterday and Ihad no idea how it got there as I never agreed to anything,. Wonder if this was the method
[+] arejaytee|6 years ago|reply
Same here, mine was from a spam email that hadn't been caught properly by Gmail and was later removed. Really great article, didn't know about the 3 settings which would have stopped me getting the notification as not accepted.
[+] jplayer01|6 years ago|reply
> Oct 31 – Google responds stating it’s a feature and the settings provide users the ability to disable

I mean, I can understand the benefit of the feature. Isn't it impractical though that the only options are everything (including spam/injected events) or nothing? Why even have the feature then if they're not going to provide any mitigation?

[+] diveanon|6 years ago|reply
I received the iPhone xs event today and it has motivated me to abandon the gsuite entirely.

It was the straw that broke the camel's back.

[+] latchkey|6 years ago|reply
Try logging into the firebase console. I had been added to two spam projects there. Filed a support request 2 days ago to get removed from them (as I cannot remove myself) and got a response saying 'we are looking into this'... now silence.
[+] vaseem|6 years ago|reply
Thanks for highliting this. This isn't getting required attention from Google.
[+] vaseem|6 years ago|reply
What happens when SPAM events are sent to Office365 users?
[+] conatus|6 years ago|reply
This advisory has no mitigation it appears. Does anyone have one? I presume one can simply turn this feature off entirely somehow?
[+] SturgeonsLaw|6 years ago|reply
1) Sign in to https://calendar.google.com/ in the browser

2) Click the Settings Gearwheel then Settings

3) Click Event Settings and set "Automatically add invitations" to "No, only display invitations to which I have replied"

Edit: if you want to disable event auto-add from Gmail while you're at it, click Events from Gmail then untick "Automatically add events from Gmail to my calendar"

[+] hkai|6 years ago|reply
There would be no problem at all if Google didn't have a bug when it adds events from spam emails into my calendar.
[+] jeanlucas|6 years ago|reply
I got 100 events in my calendar warning me to go get my phone at the repair and a suspicious link with it. It sucks.
[+] ChrisSD|6 years ago|reply
What I want to know is why the hell did Google ever think this was a good idea? I hardly even use Google Calendar and yet I had a spam notification about an "iPhone X" delivered direct to me.

The most amazing thing about this is only that spammers didn't exploit it earlier. Or maybe they did but kept a lower profile?

[+] rtkwe|6 years ago|reply
It's a convenience thing. Without spam invites it's super nice to have events from friends and family pop up without having to make sure I didn't miss anything.
[+] J_cst|6 years ago|reply
Same here, same ad - just notified abuse@google