Recently, the SlowMist security team discovered that a hacker group took advantage of Calendly's function and used "Add Custom Link" to insert malicious links on event pages to launch phishing attacks. Calendly is a very popular free calendar app for scheduling meetings and events, and is commonly used by organizations to book events or send invitations to upcoming events.
The malicious links sent by hacker groups through Calendly are well integrated with the daily work background of most victims, so these malicious links do not easily arouse suspicion. It is easy for victims to unintentionally click on malicious links, download and execute malicious code without knowing it. , thereby suffering losses.
The SlowMist security team reminds everyone that when using Calendly, if you find a link on the interface, please pay attention to identify the source and domain name of the link to avoid being attacked. You can move the mouse over the text before clicking the link. At this time, the link address corresponding to the text will be displayed in the lower left corner of the browser. Please check the link address carefully before clicking to avoid accessing phishing links.