HTML content with print styling and credential theft language
HTML smuggling with atob in message body
HTML: Template placeholders or recipient email in element class attributes
Image as content with a link to an open redirect
Impersonation: Australian Federal Police with criminal case language
Impersonation: Chrome Web Store policy
Impersonation: Employee name in subject with suspicious sender
Impersonation: Employee using fabricated identity in initial contact
Impersonation: Fake Gmail attachment
Impersonation: Fake product discount promotion
Impersonation: HR administrative center PDF password lure
Impersonation: Human Resources with link or attachment and engaging language
Impersonation: Internal corporate services
Impersonation: IT Department mailbox storage alert
Impersonation: Legal firm with copyright infringement notice
Impersonation: Recipient organization in sender display name with credential theft image
Impersonation: Salesforce fake campaign failure notification
Impersonation: SAM/SBA federal registration
Impersonation: SharePoint reply header anomaly
Impersonation: Suspected supplier impersonation with suspicious content
Inline image as message with attachment or link
Investor solicitation with organization targeting
Invoicera infrastructure abuse
Job scam (unsolicited sender)
Job scam with specific salary pattern
Link: Abused Adobe Express
Link: Adobe share from unsolicited sender
Link: Adobe share with suspicious indicators
Link: Apple App Store link to apps impersonating AI adveristing
Link: Apple App Store malicious ad manager themed apps from free email provider
Link: Base64 encoded recipient address in URL fragment with hex subdomain
Link: Base64 encoded recipient address in URL fragment with subject hash
Link: Breely link masquerading as PDF
Link: chatbot.page platform abuse
Link: Compromised WordPress site redirecting to suspicious root domain
Link: Concatenated display text concealing duplicate URLs with PDF reference
Link: Credential harvesting with excess padding evasion
Link: Credential phishing traversing Russian infrastructure
Link: Credential theft with Cloudflare tunnel and recipient targeting
Link: Credential theft with invisible Unicode character in page title from unsolicited sender
Link: Cryptocurrency fraud with suspicious links
Link: Delimited encoded path parameters (~V~ scheme)
Link: Direct link to limewire hosted file
Link: Direct POWR.io Form Builder with suspicious patterns
Link: Display text is 'unsb'
Link: Display text matches subject line
Link: Display text with excessive right-to-left mark characters
Link: Document sharing invitation template
Link: Document-themed link to newly registered domain
Link: Double base64-encoded URL path