Security
Threat actors are increasingly weaponizing event invitation-themed emails to steal credentials and install malware on victims' machines, according to a new report from Cofense Intelligence. The firm said it has observed a sustained rise in phishing campaigns disguised as event invitations since the beginning of 2025, spoofing trusted platforms including Punchbowl, Greenvelope, Paperless Post and Evite.
Invitation-themed emails now make up almost 15% of malware campaigns and just over 3% of all credential phishing campaigns Cofense Intelligence has tracked, the firm said. Behind the familiar branding, the emails deliver credential-harvesting login pages and remote access tools that give attackers persistent control of a victim's machine, according to the report.
A single malicious link can now fingerprint a recipient's device and deliver different payloads to desktop and mobile users simultaneously, Cofense Intelligence said, expanding each campaign's reach without additional effort from the attacker. In one campaign the firm documented, a malicious URL delivered ConnectWise RAT if the recipient opened the link on a Windows machine, but redirected to a credential phishing page if opened on a mobile device — giving the attacker access regardless of which device the victim used.
Cofense Intelligence said visual polish is no longer a reliable signal of legitimacy, noting that threat actors are now producing invitation lures indistinguishable from genuine platform communications. That shift undermines appearance-based detection for both employees and automated filters, according to the firm.
Emotional subject lines drive click-through
The campaigns rely heavily on emotional appeals rather than technical sophistication, Cofense Intelligence said. Subject lines commonly use phrases designed to create urgency or warmth, and the firm cited examples including "Please don't miss out!" and "Dear friends and family, join me for a joyful gathering." Some campaigns use names familiar to the victim, such as a coworker or family member, to lower the recipient's guard before they click.
In one case detailed in the report, a Punchbowl-spoofing email delivered ConnectWise RAT, a legitimate remote access tool built by ScreenConnect that is frequently abused by attackers, according to Cofense Intelligence. Because the tool is also used legitimately by IT teams, the firm said automated security defenses often allow it to run unchallenged despite its capabilities. A separate Evite-spoofing campaign used "friends and family" language to deliver Datto RMM, another legitimate remote monitoring tool that has been abused for malicious access, the report said.
Credential phishing pages mimic major platforms
Cofense Intelligence also documented invitation-themed campaigns built purely around credential theft. In one example, the firm said a generic invitation-themed email led to an AI-generated landing page designed to capture a victim's username and password. Another campaign used a landing page spoofing the Google login screen, incorporating recognizable branding from Google, Apple, Instagram and TikTok to appear more legitimate, according to the report.
Recommendations for security teams
Cofense Intelligence said the campaigns succeed because they exploit social trust rather than technical vulnerabilities, making them effective even against employees who follow standard security practices. "An employee who believes they have been invited to their coworker's retirement party will find a way to click the link," the report said.
The firm recommended blocking malicious domains, enforcing multi-factor authentication, and alerting on suspicious attachments as measures that can significantly reduce exposure, while stressing that human awareness training remains a critical control alongside technical defenses. Cofense Intelligence said it continues to track invitation-themed phishing activity and has published indicators of compromise from the campaigns referenced in the report.
Invitation-themed emails now make up almost 15% of malware campaigns and just over 3% of all credential phishing campaigns Cofense Intelligence has tracked, the firm said. Behind the familiar branding, the emails deliver credential-harvesting login pages and remote access tools that give attackers persistent control of a victim's machine, according to the report.
A single malicious link can now fingerprint a recipient's device and deliver different payloads to desktop and mobile users simultaneously, Cofense Intelligence said, expanding each campaign's reach without additional effort from the attacker. In one campaign the firm documented, a malicious URL delivered ConnectWise RAT if the recipient opened the link on a Windows machine, but redirected to a credential phishing page if opened on a mobile device — giving the attacker access regardless of which device the victim used.
Cofense Intelligence said visual polish is no longer a reliable signal of legitimacy, noting that threat actors are now producing invitation lures indistinguishable from genuine platform communications. That shift undermines appearance-based detection for both employees and automated filters, according to the firm.
Emotional subject lines drive click-through
The campaigns rely heavily on emotional appeals rather than technical sophistication, Cofense Intelligence said. Subject lines commonly use phrases designed to create urgency or warmth, and the firm cited examples including "Please don't miss out!" and "Dear friends and family, join me for a joyful gathering." Some campaigns use names familiar to the victim, such as a coworker or family member, to lower the recipient's guard before they click.
In one case detailed in the report, a Punchbowl-spoofing email delivered ConnectWise RAT, a legitimate remote access tool built by ScreenConnect that is frequently abused by attackers, according to Cofense Intelligence. Because the tool is also used legitimately by IT teams, the firm said automated security defenses often allow it to run unchallenged despite its capabilities. A separate Evite-spoofing campaign used "friends and family" language to deliver Datto RMM, another legitimate remote monitoring tool that has been abused for malicious access, the report said.
Credential phishing pages mimic major platforms
Cofense Intelligence also documented invitation-themed campaigns built purely around credential theft. In one example, the firm said a generic invitation-themed email led to an AI-generated landing page designed to capture a victim's username and password. Another campaign used a landing page spoofing the Google login screen, incorporating recognizable branding from Google, Apple, Instagram and TikTok to appear more legitimate, according to the report.
Recommendations for security teams
Cofense Intelligence said the campaigns succeed because they exploit social trust rather than technical vulnerabilities, making them effective even against employees who follow standard security practices. "An employee who believes they have been invited to their coworker's retirement party will find a way to click the link," the report said.
The firm recommended blocking malicious domains, enforcing multi-factor authentication, and alerting on suspicious attachments as measures that can significantly reduce exposure, while stressing that human awareness training remains a critical control alongside technical defenses. Cofense Intelligence said it continues to track invitation-themed phishing activity and has published indicators of compromise from the campaigns referenced in the report.
See What’s Next in Tech With the Fast Forward Newsletter
Tweets From @varindiamag
Nothing to see here - yet
When they Tweet, their Tweets will show up here.




