{"id":416932,"date":"2026-09-20T14:31:38","date_gmt":"2026-09-20T14:31:38","guid":{"rendered":"https:\/\/malwaretips.com\/blogs\/?p=416932"},"modified":"2026-09-20T14:31:38","modified_gmt":"2026-09-20T14:31:38","slug":"fake-calendar-credit-notes-install-remote-access","status":"publish","type":"post","link":"https:\/\/malwaretips.com\/blogs\/fake-calendar-credit-notes-install-remote-access\/","title":{"rendered":"Fake Calendar Credit Notes Install Remote Access"},"content":{"rendered":"<p>A meeting invitation appears in your inbox and on your calendar. It says a payment of $1,109.08 needs attention and offers a link to view a credit note.<\/p><div id=\"mwtad3551857718\" class=\"gas_fallback-ad_309684--placement_406659\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3957935887\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<p>The sender uses Gmail, the invitation travels through Google Calendar, and the link may briefly show a Google address. Those familiar pieces can make the event feel safer than an ordinary unsolicited attachment.<\/p>\n<p>The calendar entry is the beginning of the attack, not the document it promises. Following the trail can install a legitimate remote-support program that has been configured for someone else\u2019s control.<\/p><div id=\"mwtad4210836434\" class=\"gas_fallback-ad_381396-ad_309685-placement_406667\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"1471373341\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<figure><img loading=\"lazy\" decoding=\"async\" width=\"1200\" height=\"675\" src=\"data:image\/gif;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw==\" class=\"wp-image-416933 lazyload\" alt=\"Fraudulent Google Calendar credit note invitation claiming a recent payment\" title=\"\" sizes=\"auto, (max-width: 1200px) 100vw, 1200px\" data-src=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/fake-calendar-credit-notes-install-remote-access-1-final.png\" data-srcset=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/fake-calendar-credit-notes-install-remote-access-1-final.png 1200w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/fake-calendar-credit-notes-install-remote-access-1-final-300x169.png 300w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/fake-calendar-credit-notes-install-remote-access-1-final-1024x576.png 1024w\"><\/figure>\n<div id=\"mwtad2494899671\" class=\"gas_fallback-ad_309746-ad_309685-placement_406660\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"4456629336\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>Overview<\/h2>\n<h3>The attack arrives as both email and a calendar event<\/h3>\n<p>The calendar credit note scam uses an invitation file, often called an ICS invitation, to put the same lure in two places. The recipient may see it as an email and as an event added to the calendar.<\/p>\n<p>This dual delivery matters. An email security filter might remove the message while the calendar entry remains visible, complete with a notification and a clickable link.<\/p>\n<h3>A fake payment creates business urgency<\/h3>\n<p>In the campaign documented by Sublime Security, the invitation referenced a recent $1,109.08 payment and directed the recipient to a supposed credit note. The financial language makes the event resemble a vendor, refund, or accounting issue that cannot be ignored.<\/p><div id=\"mwtad854753580\" class=\"gas_fallback-ad_309686-ad_309685-placement_406668\" style=\"margin-top: 50px;margin-right: 10px;margin-bottom: 50px;margin-left: 10px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"6935453015\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<p>The sender is a first-time Gmail contact despite the business-themed request. The link leads through Google\u2019s automatic redirect to a page hosted on Framer\u2019s free website service.<\/p>\n<h3>The download installs remote access instead of a document<\/h3>\n<p>The landing page tells the visitor to click \u201cVIEW HERE\u201d for the credit note. Rather than opening a PDF or accounting record, it delivers a roughly 10 MB installer named ScreenConnect.ClientSetup.msi.<\/p>\n<p>ScreenConnect is a legitimate remote monitoring and management product. The malicious installer includes configuration that connects the victim\u2019s computer to the attacker\u2019s remote-control infrastructure.<\/p><div id=\"mwtad1697715482\" class=\"gas_fallback-ad_381401-ad_309685-placement_406669\" style=\"margin-top: 50px;margin-right: 10px;margin-bottom: 50px;margin-left: 10px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"5315249587\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<ul>\n<li>The lure is delivered through a calendar invitation and email.<\/li>\n<li>The event claims a $1,109.08 payment requires attention.<\/li>\n<li>A Gmail sender makes the message inexpensive and easy to distribute.<\/li>\n<li>The invitation link is rewritten through a Google redirect.<\/li>\n<li>The landing page uses a free Framer website.<\/li>\n<li>The promised credit note is actually an MSI installer.<\/li>\n<li>The installer deploys a configured ScreenConnect remote-access client.<\/li>\n<li>Google, Framer, and ScreenConnect are being abused, not accused of running the attack.<\/li>\n<\/ul>\n<div id=\"mwtad454957320\" class=\"gas_fallback-ad_309747-ad_309685-placement_406661\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"9589536513\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>Why Calendar Invitations Create a Security Blind Spot<\/h2>\n<p>People are used to clicking invitations from coworkers, vendors, clinics, and delivery services. Calendar software tries to be helpful by recognizing dates, creating reminders, and placing meeting details where they will be seen later.<\/p>\n<p>Attackers exploit that helpful behavior. The invitation can arrive through a trusted provider and still contain untrusted text and links supplied by the person who created the event.<\/p>\n<div id=\"mwtad2181047059\" class=\"gas_fallback-ad_381404-ad_309685-placement_406670\" style=\"margin-top: 50px;margin-right: 10px;margin-bottom: 50px;margin-left: 10px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"8735619847\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><p>Email and calendar data may also travel through different protocols and security paths. Sublime found that an organization could block the email copy while the corresponding event still reached the target\u2019s calendar.<\/p>\n<figure><img loading=\"lazy\" decoding=\"async\" width=\"1200\" height=\"675\" src=\"data:image\/gif;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw==\" class=\"wp-image-416934 lazyload\" alt=\"Fake credit note download page reached from a malicious calendar invitation\" title=\"\" sizes=\"auto, (max-width: 1200px) 100vw, 1200px\" data-src=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/fake-calendar-credit-notes-install-remote-access-2-final.png\" data-srcset=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/fake-calendar-credit-notes-install-remote-access-2-final.png 1200w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/fake-calendar-credit-notes-install-remote-access-2-final-300x169.png 300w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/fake-calendar-credit-notes-install-remote-access-2-final-1024x576.png 1024w\"><\/figure>\n<p>The event may generate another notification shortly before its scheduled time. That reminder can revive the lure hours or days after the original email was ignored. A recipient then sees a business-sounding alert without remembering how it arrived.<\/p>\n<p>Trusted infrastructure adds another layer of cover. Gmail, Google Calendar, Google\u2019s link rewriting, Framer, and a ScreenConnect trial all reduce the attacker\u2019s cost and make parts of the chain look familiar.<\/p>\n<div id=\"mwtad1235949793\" class=\"mwtadp5 mwtadentity-placement\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"https:\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\"\r\n     crossorigin=\"anonymous\"><\/script>\r\n<ins class=\"adsbygoogle\"\r\n     style=\"display:block; text-align:center;\"\r\n     data-ad-layout=\"in-article\"\r\n     data-ad-format=\"fluid\"\r\n     data-ad-client=\"ca-pub-7750719144850257\"\r\n     data-ad-slot=\"8560433799\"><\/ins>\r\n<script>\r\n     (adsbygoogle = window.adsbygoogle || []).push({});\r\n<\/script><\/div><p>None of those services validates the business claim in the invitation. A Google-hosted event can be fraudulent, just as an envelope delivered by a legitimate postal service can contain a fraudulent invoice.<\/p>\n<div id=\"mwtad2429938248\" class=\"gas_fallback-ad_309748-ad_309685-placement_406662\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3906789406\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>Company, Address, and Fulfillment Checks<\/h2>\n<h3>The first-time Gmail sender does not fit the business story<\/h3>\n<p>A genuine credit note should come from a company you recognize and normally do business with. The message should identify an invoice, order, supplier, or account that can be confirmed through existing records.<\/p>\n<p>An unexpected Gmail address discussing a four-figure payment is a strong warning. Contact the vendor using the phone number or portal already stored in your accounting system, not the details supplied in the invitation.<\/p>\n<h3>The visible Google link only redirects elsewhere<\/h3>\n<div id=\"mwtad412092793\" class=\"mwtadp6 mwtadentity-placement\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"https:\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\"\r\n     crossorigin=\"anonymous\"><\/script>\r\n<ins class=\"adsbygoogle\"\r\n     style=\"display:block; text-align:center;\"\r\n     data-ad-layout=\"in-article\"\r\n     data-ad-format=\"fluid\"\r\n     data-ad-client=\"ca-pub-7750719144850257\"\r\n     data-ad-slot=\"4034304343\"><\/ins>\r\n<script>\r\n     (adsbygoogle = window.adsbygoogle || []).push({});\r\n<\/script><\/div><p>Google Calendar rewrites links in invitation emails through a Google URL. That intermediate address does not mean Google owns or reviewed the final page. In this campaign, the redirect resolved to a Framer subdomain named to sound secure.<\/p>\n<p>Pause after the final page loads and read the complete domain. Words such as \u201csecured,\u201d \u201cbilling,\u201d or \u201ccredit-note\u201d in a subdomain can be chosen by an attacker and do not create authority.<\/p>\n<h3>A credit note should not require an MSI installer<\/h3>\n<p>Credit notes are normally documents or records inside an established business portal. An MSI file is a Windows software installer. That mismatch is enough to stop, even if the download uses a familiar product name.<\/p>\n<p>A remote-support program may be completely legitimate in another context. It becomes dangerous when an unknown sender preconfigures it to grant access and disguises the installer as a financial document.<\/p>\n<h3>Independent telemetry confirms the malicious campaign<\/h3>\n<p><a href=\"https:\/\/sublime.security\/blog\/sublime-observes-massive-uptick-in-ics-phishing-and-calendar-based-malware-attacks\/\" rel=\"noopener noreferrer\" target=\"_blank\">Sublime Security documented the calendar lure, Framer page, ScreenConnect download, and malicious configuration<\/a>. Its researchers also reported a sharp rise in calendar-based attacks during August and September 2026.<\/p>\n<p>The evidence supports treating this as a confirmed malware-delivery campaign. It does not make every unsolicited calendar invitation malicious, but it shows why the event content must be verified separately.<\/p>\n<div id=\"mwtad2060998983\" class=\"gas_fallback-ad_318930-ad_309685-placement_406663\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3818335085\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>How the Calendar Credit Note Scam Works<\/h2>\n<h3>Step 1: The attacker creates a financial calendar event<\/h3>\n<p>The attacker uses a free Gmail account to send an invitation. The event mentions a recent payment and frames the attached link as the place to review a credit note or resolve the transaction.<\/p>\n<p>A precise amount such as $1,109.08 gives the story the texture of a real accounting entry. The recipient may worry that a payment was made without authorization or that a refund is waiting.<\/p>\n<h3>Step 2: The invitation appears in two locations<\/h3>\n<p>The recipient sees the event in the inbox, and calendar settings may add it automatically. Even if one copy is removed, another may remain in the calendar and produce reminders.<\/p>\n<p>This repeated visibility is not proof of legitimacy. It is a side effect of how invitations are designed to help people coordinate meetings.<\/p>\n<h3>Step 3: A Google redirect leads to a free website<\/h3>\n<p>Clicking from the invitation passes through a google.com redirect created by Calendar\u2019s link handling. The browser then opens an attacker-made page on a Framer website.<\/p>\n<p>The landing page uses security-flavored wording and a \u201cVIEW HERE\u201d button. The free site builder provides polished hosting without proving who created the page.<\/p>\n<figure><img loading=\"lazy\" decoding=\"async\" width=\"1200\" height=\"675\" src=\"data:image\/gif;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw==\" class=\"wp-image-416935 lazyload\" alt=\"ScreenConnect client installer presented as a calendar credit note download\" title=\"\" sizes=\"auto, (max-width: 1200px) 100vw, 1200px\" data-src=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/fake-calendar-credit-notes-install-remote-access-3-final.png\" data-srcset=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/fake-calendar-credit-notes-install-remote-access-3-final.png 1200w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/fake-calendar-credit-notes-install-remote-access-3-final-300x169.png 300w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/fake-calendar-credit-notes-install-remote-access-3-final-1024x576.png 1024w\"><\/figure>\n<h3>Step 4: The victim downloads an installer instead of a credit note<\/h3>\n<p>The button downloads ScreenConnect.ClientSetup.msi. Windows environments with appropriate controls may block it, but a victim can still be prompted to keep or run the file.<\/p>\n<p>The filename contains the name of a real support product, which can make the installer appear administrative. The invitation never had a valid reason to install remote-control software.<\/p>\n<h3>Step 5: ScreenConnect connects to the attacker<\/h3>\n<p>The MSI contains the server and configuration information needed to repurpose ScreenConnect as a command channel. Once installed, it can give the remote operator access to the computer.<\/p>\n<p>The exact capabilities depend on configuration and privileges, but remote management tools can allow screen viewing, keyboard and mouse control, file transfer, command execution, and additional software installation.<\/p>\n<h3>Step 6: Remote access enables the next fraud<\/h3>\n<p>The operator may search for stored passwords, email sessions, financial documents, browser cookies, or accounting access. They can also install additional malware or use the compromised mailbox to send believable messages to coworkers and vendors.<\/p>\n<p>A victim may focus on the missing credit note and not notice a background service maintaining access. That is why simply deleting the calendar event does not clean a computer after the installer has run.<\/p>\n<div id=\"mwtad3818112914\" class=\"gas_fallback-ad_381388-ad_309685-placement_406705\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3191649120\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>How to Remove a Malicious Calendar Invitation Safely<\/h2>\n<p>Do not click the event link to identify the organizer or discover what the payment means. Open the calendar provider\u2019s event controls, report the invitation as spam or phishing, and remove it without sending a response when that option is available.<\/p>\n<p>Declining an event can notify its organizer that the mailbox is monitored. Provider behavior varies, so workplace users should follow the organization\u2019s approved reporting path rather than replying to the sender.<\/p>\n<p>Search the calendar for related events from the same address, repeated subject, or similar payment wording. Then check the inbox, trash, spam folder, and mail rules for matching messages. A campaign may schedule multiple reminders or send variants to several employees.<\/p>\n<p>Administrators should review automatic invitation settings. Restricting which invitations appear on a calendar, monitoring external organizers, and removing both the message and event can reduce the gap this technique exploits.<\/p>\n<p>Also warn accounting staff about the exact amount and credit-note story. If the lure reached one employee, another recipient may call a fake number, run the file, or forward it internally believing it is a real supplier issue.<\/p>\n<p>Keep the reported event until administrators have the organizer address and link, then remove it through the provider\u2019s controls. That preserves useful evidence without opening the payload.<\/p>\n<div id=\"mwtad1857904086\" class=\"gas_fallback-ad_381392-ad_309685-placement_406664\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"2944237110\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>Warning Signs in Calendar and Credit Note Messages<\/h2>\n<ul>\n<li>The invitation comes from a first-time Gmail sender.<\/li>\n<li>You do not recognize the company, payment, or event organizer.<\/li>\n<li>A precise amount creates urgency without an invoice or account reference.<\/li>\n<li>The same lure appears in both email and the calendar.<\/li>\n<li>The link ultimately loads a free site-builder subdomain.<\/li>\n<li>The page uses authority words in the subdomain instead of a real company domain.<\/li>\n<li>A document request downloads an MSI, EXE, ZIP, or other program.<\/li>\n<li>The installer is a remote support or monitoring tool.<\/li>\n<li>The sender asks you to override a Windows or browser warning.<\/li>\n<li>Your vendor portal and accounting records show no matching transaction.<\/li>\n<\/ul>\n<p>Do not accept, decline, or click solely to make the event disappear. Report it as spam or phishing and remove the calendar entry through the provider\u2019s controls.<\/p>\n<div id=\"mwtad708779674\" class=\"gas_fallback-ad_381392-ad_309685-placement_406665\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"2944237110\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>What to Do if You Have Fallen Victim to This Scam<\/h2>\n<ol>\n<li><strong>If you only opened the invitation, do not follow the link.<\/strong> Report the message and remove the event from the calendar. Check whether it was shared with other people in your organization.<\/li>\n<li><strong>If you downloaded the MSI but did not run it, delete it.<\/strong> Empty the recycle bin and scan the file\u2019s former location. Do not open it again to see what it does.<\/li>\n<li><strong>If you ran the installer, disconnect the computer from the network.<\/strong> Turn off Wi-Fi or remove the network cable to interrupt remote access. Do not continue using the device for email or banking.<\/li>\n<li><strong>Tell your IT or security team immediately.<\/strong> Provide the invitation, sender, URLs, downloaded filename, time of execution, and any ScreenConnect prompts. Quick containment can protect other accounts and devices.<\/li>\n<li><strong>Remove unauthorized remote-management software.<\/strong> A professional should identify services, startup entries, configuration, and any additional payloads before declaring the system clean. Uninstalling the visible client alone may miss follow-on changes.<\/li>\n<li><strong>Change passwords from a separate trusted device.<\/strong> Prioritize email, workplace single sign-on, banking, password managers, and any account used while remote access was active. Revoke sessions and check MFA methods.<\/li>\n<li><strong>Review mail and financial activity.<\/strong> Look for forwarding rules, sent messages, changed payment instructions, new vendors, card charges, and bank transfers. Warn contacts if the mailbox may have sent messages in your name.<\/li>\n<li><strong>Run security checks after containment.<\/strong> Malwarebytes can detect many malicious installers and follow-on payloads. AdGuard can reduce exposure to known phishing pages, but neither substitutes for incident response after remote access was granted.<\/li>\n<li><strong>Report the abused services.<\/strong> Notify the calendar provider, website host, remote-access vendor, and relevant fraud authority. Use official reporting pages found independently.<\/li>\n<\/ol>\n<h2>Frequently Asked Questions<\/h2>\n<h3>What is an ICS calendar invitation?<\/h3>\n<p>ICS is a common calendar data format used to share events. The format is legitimate, but an attacker can place deceptive text and malicious links inside an event.<\/p>\n<h3>Can an event remain after the email is blocked?<\/h3>\n<p>Yes. Email and calendar systems can process the invitation separately. Depending on settings, the event may remain visible even when the inbox message is removed.<\/p>\n<h3>Is ScreenConnect malware?<\/h3>\n<p>ScreenConnect is legitimate remote-support software. In this campaign, attackers abused a configured client to gain unauthorized remote access.<\/p>\n<h3>Why does the link begin with google.com?<\/h3>\n<p>Google Calendar can rewrite event links through a Google redirect. That first address forwards to the real destination and does not certify it as safe.<\/p>\n<h3>What if I downloaded the file but never opened it?<\/h3>\n<p>The documented remote-access installation requires the MSI to run. Delete the file, scan the device, and stay alert, but the risk is much lower than after execution.<\/p>\n<h3>Does deleting the calendar event remove the program?<\/h3>\n<p>No. Removing the event only removes the lure. If the installer ran, the computer needs separate containment, investigation, and cleanup.<\/p>\n<h2>The Bottom Line<\/h2>\n<p>The calendar credit note scam hides a remote-access installer behind a normal-looking business invitation. Trusted delivery services make the route familiar, but they do not validate the sender\u2019s payment story.<\/p>\n<p>A credit note should never require ScreenConnect or any other remote-management installer. Close the page the moment a supposed document becomes software.<\/p>\n<p>If the MSI ran, treat the computer as remotely accessible. Disconnect it, alert IT, secure accounts from another device, and investigate beyond the calendar entry.<\/p>\n<div id=\"mwtad1678855966\" class=\"gas_fallback-ad_176819-ad_309685-placement_406666\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"8386082122\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>A meeting invitation appears in your inbox and on your calendar. It says a payment of $1,109.08 needs attention and offers a link to view a credit note. The sender uses Gmail, the invitation travels &#8230; <\/p>\n<p class=\"read-more-container\"><a title=\"Fake Calendar Credit Notes Install Remote Access\" class=\"read-more button\" href=\"https:\/\/malwaretips.com\/blogs\/fake-calendar-credit-notes-install-remote-access\/#more-416932\" aria-label=\"Read more about Fake Calendar Credit Notes Install Remote Access\">Read more<\/a><\/p>\n","protected":false},"author":51,"featured_media":416933,"comment_status":"open","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[49],"tags":[],"class_list":["post-416932","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-scam-reports","masonry-post","generate-columns","tablet-grid-50","mobile-grid-100","grid-parent","grid-50","resize-featured-image"],"_links":{"self":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/416932","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/users\/51"}],"replies":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/comments?post=416932"}],"version-history":[{"count":2,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/416932\/revisions"}],"predecessor-version":[{"id":417208,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/416932\/revisions\/417208"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/media\/416933"}],"wp:attachment":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/media?parent=416932"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/categories?post=416932"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/tags?post=416932"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}