Skip to main content

You're Invited to get Phished! Why Invitation-themed Emails Remain Effective

August 12, 2026

By: Micah DeHarty, Intelligence Team

Threat actors are weaponizing party invitation-themed emails to steal credentials and install malware on victims’ machines. Cofense Intelligence has observed a sustained rise in phishing campaigns disguised as event invitations, spoofing trusted platforms such as Punchbowl, Greenvelope, Paperless Post, and Evite. Behind the familiar branding, these emails deliver credential-harvesting login pages and remote access tools that give threat actors persistent control of a victim’s machine. The same link can fingerprint the recipient’s device and deliver different payloads to desktop and mobile users simultaneously, expanding the reach of each campaign without additional effort. The technology behind these campaigns has evolved, but the underlying lure has not. People are naturally curious about invitations, and attackers continue to exploit that instinct.

Key Points

  • Threat actors are using event invitation-themed emails to deliver malware and credential phishing content.
  • Emails are spoofing popular services such as Punchbowl, Greenvelope, Paperless Post, and Evite.
  • There is a steady upward trend of event invitation-themed emails since the beginning of 2025.
  • Invitation-themed emails make up almost fifteen percent of malware campaigns and just over three percent of all credential phishing campaigns seen by Cofense Intelligence.
  • Visual polish is no longer a reliable signal of a legitimate email. Threat actors are producing invitation lures that are indistinguishable from genuine platform communications, making appearance-based detection unreliable for both employees and automated filters.
  • A single malicious link can target both desktop and mobile users simultaneously. Threat actors are embedding device-detection logic that delivers different remote access malware to Windows machines and MacOS machines, as well as credential phishing pages for mobile devices, all from the same URL. This triples the potential yield of each campaign.

Why Does This Work?

Invitation-themed phishing emails have long been a part of the phishing threat landscape. In the past year, there has been a slight uptick in their use, and for good reason. Often, threat actors try to invoke an emotional response from an email recipient to trick them into making a decision they normally would not. In the case of invitation-themed emails, threat actors are relying on the fact that recipients will be intrigued by a party invitation and want to know more about the event they are being invited to. 

Subject lines in these emails commonly use phrasing that invokes an emotional response. Some examples of that are “Please don’t miss out!”, “A fabulous event invitation just for you!”, and “Dear friends and family, join me for a joyful gathering”. 

The common theme among these is that the threat actor seeks to gain the recipient's trust and attention. Other phishing campaigns will use this same tactic, but with invitation-themed emails, an emotional response is heavily relied upon. Another key factor used in invitation-themed phishing campaigns is brand recognition. Multiple electronic invitation platforms are commonly spoofed in these campaigns. Brands such as Punchbowl, Greenvelope, Paperless Post, and Evite top the list of most common invitation spoofs.

You're_Invited_to_get_Phished!_Why_invitation_themed_emails_remain_effective_Figure1

Figure 1: Line graph showing the increase in percentage of Invitation-themed Active Threat Reports from Q1 2025 to Q2 2026.

How These Emails Deliver Malware

Threat actors are using invitation-themed phishing emails to deliver several types of malware. These phishing emails use fake event invitations that request the recipient to click on a link to accept. When clicked, the link goes to a page containing another link that downloads the malware depending on the operating system. At Cofense Intelligence, we maintain a database of Active Threat Reports (ATR) within our ThreatHQ platform. These ATRs detail different threat types seen by our Intelligence Analysts, such as Credential Phishing and types of malware delivered via email, as well as the context of the campaign detailed in the ATR.

In this first example in Figure 2 from ATR 417375, the attacker is using a Punchbowl-branded email and landing page. The brand spoofing is used alongside a compelling subject line and event name to deliver ConnectWise RAT. ConnectWise RAT is an abused, technically legitimate, remote access tool (RAT) published by ScreenConnect that is used to take control over the victim’s machine. Because ConnectWise RAT is also a legitimate IT tool, automated security defenses frequently allow it to run unchallenged despite its capabilities. In some cases, threat actors will use names that are familiar to the victim, such as a coworker, friend, or family member, to gain the trust of the victim. 

When the recipient sees that they have received an invitation from someone they know, oftentimes they let their guard down and click on the link. This email also includes “for desktop only” in the subject line because they are delivering a malware payload that will not work on a mobile device.

You're_Invited_to_get_Phished!_Why_invitation_themed_emails_remain_effective_Figure2

Figure 2: Punchbowl-spoofing, invitation-themed email used to deliver ConnectWise RAT via an embedded URL from ATR 417375.

In the second example shown in Figure 3, a threat actor is using an Evite-spoofing email that uses a lengthy subject line to draw in the users’ attention. The subject line uses light, heartfelt language and includes “friends and family” to appeal to the victims’ feelings. In cases like this, the victim may feel obligated to open and click on an invitation from a family member without hesitation. Once the user clicks on this email, the email delivers Datto RMM, another abused RAT.

You're_Invited_to_get_Phished!_Why_invitation_themed_emails_remain_effective_Figure3

Figure 3: Evite-spoofing, invitation-themed email used to deliver Datto RMM via an embedded URL from ATR 416254.

How These Emails Steal Your Login Credentials

Threat actors will also use these invitation-themed emails in credential phishing attacks. In this credential phishing example from ATR 416670, the threat actor is using an invitation-themed email and an AI-generated landing page to trick the recipient into entering their username and password. 

In Figure 4, the threat actor is appealing to the victim’s feeling of not wanting to miss out on an important event. This email is more generic and does not spoof a specific brand, but much like the other phishing emails in previous examples, it appeals to the victim’s emotions to get them to click the link to the credential phishing page.

You're_Invited_to_get_Phished!_Why_invitation_themed_emails_remain_effective_Figure4

Figure 4: Invitation-themed email used to deliver a credential phishing page via an embedded URL from ATR 416670.

In another invitation-themed credential phishing campaign, seen in Figure 5 and ATR 417200, Cofense Intelligence observed a threat actor using a generic invitation-themed email with a landing page that spoofs the Google login page. Although this email does not spoof an e-delivery site specifically, it does use popular branding such as Google, Apple, Instagram, and TikTok to make the email look more legitimate. 

You're_Invited_to_get_Phished!_Why_invitation_themed_emails_remain_effective_Figure5

Figure 5: Invitation-themed email used to deliver a credential phishing page via an embedded URL from ATR 417200.

In this final example in Figure 6 from ATR 417310, Cofense Intelligence observed a threat actor combining both credential phishing and malware. When creating the malicious link for this email, the threat actor implemented a check to see what device the victim was using when the link was clicked. In this case, the URL in the email downloads ConnectWise RAT if the recipient is on a Windows computer. If the recipient clicks on the link using their mobile device, the URL redirects to a credential phishing page. Opening the link on any device still provides the threat actor with access in some way. This is a common occurrence with current invitation-themed campaigns. Using this tactic allows threat actors to have a broader attack surface regardless of whether the target is at their work desktop or on their personal phone.

Not that long ago, users were taught to watch out for emails that had spelling mistakes or other mistakes in branding, but in the current threat landscape, threat actors are using very polished messages that look exactly like a real email. In the age of AI, visual polish is no longer a reliable indicator of legitimacy in any means of communication.

You're_Invited_to_get_Phished!_Why_invitation_themed_emails_remain_effective_Figure6

Figure 6: Paperless Post-spoofing, invitation-themed email used to deliver a credential phishing page or ConnectWise RAT via an embedded URL from ATR 417310.

Conclusion

The campaigns documented here share a common thread: they succeed not because they are technically sophisticated, but because they are socially convincing. A well-crafted invitation-themed email works because people trust communications that appear to be from people or platforms that they recognize. Because these emails exploit social trust rather than technical vulnerabilities, they are effective even against employees who follow standard practice. 

Blocking malicious domains, enforcing multi-factor authentication, and alerting on suspicious attachments may significantly reduce exposure, but an employee who believes they have been invited to their coworker’s retirement party will find a way to click the link. 

Human awareness training has become a critical control alongside technical defenses. Cofense Intelligence continues to track invitation-themed phishing activity across the threat landscape. Organizations looking to understand their current exposure can find campaign IOCs in the ATRs referenced throughout this report.

Mitigations

Invitation-themed emails have similar remediation steps to most other phishing attacks.

  • Update employee security awareness training to reflect current lure themes, specifically Adobe document requests, SSA benefit notices, IRS refund emails, and Zoom meeting invitations. Employees who have been trained on real, current threats are more likely to pause before clicking. Simulation exercises should use these exact scenarios, not outdated generic examples.
  • Businesses can use tools and software provided by Cofense, such as Triage and Vision, to prevent initial access and future attacks. Triage allows for an in-depth breakdown of the phishing email, making it easier to analyze and act upon. Vision uses human insight and AI precision to quarantine and remove malicious emails from inboxes.
  • Establish and enforce a software allowlist for remote access tools. Any remote access tool not on that list, including ConnectWise, SimpleHelp, Atera, and GoTo RAT, should be blocked from installing on corporate devices. Organizations that do not have an allowlist should, at a minimum, block the digital certificates associated with remote access tools they do not use.
  • Deploy email security technologies that flag when the sending domain does not match the brand displayed. Invitation spoofs rely on that mismatch not being noticed.
  • Deploy enterprise password managers. When an employee visits a party invitation themed page, a password manager will refuse to fill in credentials because the domain does not match the legitimate service. This provides a structural catch that works regardless of how convincing the branding is and complements employee training rather than replacing it.
  • Have a simple and easy way for employees to report emails. Cofense Triage and Vision exist for exactly this purpose. Employees who receive these emails and report them quickly give security teams the chance to block infrastructure before other recipients click. A well-trained employee who flags an invitation-themed email is a detection tool no automated system can replicate.