The NJCCIC observed a Calendly phishing campaign targeting New Jersey State employees. The phishing email purports to be a partnership opportunity with an attached Request for Quotation (RFQ) for a project plan. At first glance, an RFQ file in an Adobe PDF format appears attached in the email. However, upon further inspection, this section—displaying the file format icon, filename, and file size with a functional drop-down menu—is actually a JPG or PNG image. If the target hovers the mouse over the image, it displays a link that, if clicked, directs the target to the legitimate Calendly platform.

On the Calendly page, threat actors continue their malicious scheme. They claim that the secure document contains confidential information and is encrypted through Adobe. This campaign requires an updated version of Adobe to review the document and instructs the target to download a “ScreenConnect” file to complete the Adobe installation. If downloaded and installed, the threat actors can establish remote access to the target’s system, maintain persistence, deploy additional malware, and conduct further malicious activity.
Recommendations
- Exercise caution with unexpected or unsolicited requests or communications from known senders or legitimate platforms that contain links, attachments, downloads, software, or remote access utilities.
- Confirm requests from senders using contact information obtained from verified, official sources before taking any action.
- Hover your mouse over a link to verify the exact URL destination before interacting with it.
- Navigate directly to legitimate websites and verify before submitting account credentials, providing personal or financial information, or downloading files.
- Enable multi-factor authentication (MFA) and keep systems and browsers up to date.
- If victimized, disconnect from the internet and run anti-virus/anti-malware scans.
- If sensitive information was entered, change passwords for compromised accounts, monitor for unauthorized activity, and review the Identity Theft and Compromised PII NJCCIC Informational Report for additional recommendations and resources.

