News
Malicious event invitations delivering ScreenConnect malware
Duke is alerting faculty, staff, and students about an ongoing phishing campaign using fake event and Zoom meeting invitations to trick recipients into downloading malicious software.
Malicious event-invitation emails, made to resemble legitimate invitations from services such as Paperless Post, Punchbowl, Sendomatic, and similar platforms, are being sent to personal and Duke email addresses. The fake invitations persuade recipients to visit a webpage that downloads and installs malicious software.
In another variation, the attackers send a fake Zoom meeting invitation and instructs the recipient to download a “Zoom update” from a redirected site.
If you received a malicious event-invitation email and have already downloaded the software, immediately contact the IT Security Office and/or your local IT support.
Legitimate invitation emails should not require you to download or run software to view their content. A common warning sign is language such as “open from a computer,” followed by a request to view the invitation or download software. Verify invitations before clicking.
These messages can be convincing because they resemble routine invitations and may use familiar sender names or subject lines.
The event-invitation emails sent to personal accounts accessed on Duke-owned devices, could put that device at risk. Similarly, messages forwarded from Duke accounts to personal accounts could compromise personal devices when opened.
Note: Forwarding Duke email to a personal address removes Duke mail-security protections and limits the IT Security Office’s ability to investigate. For example, if a malicious message is opened on a personal device then the ITSO may have limited or no visibility into a resulting device compromise.
What to look for:
- Unexpected event invitations
Links that lead to software downloads - Messages that instruct you to “open from a computer” or otherwise push you toward installing something
- Any invitation that asks you to download or run software to view the content
What to do:
- Do not click or accept unexpected invitations until you verify them
- Do not download or run any software that is delivered through an invitation email
- If you are expecting an invitation but something looks unusual, verify it through another trusted channel before opening it
- Report suspicious messages using the Report Message button in your mail client
Please share this information broadly. If you have any questions, please contact security@duke.edu. Thank you for helping keep the community safe.