Attachment: Web files with suspicious comments
Attachment: Word document with hyperlink and fraud language
BEC: Executive coaching vendor impersonation
Body: AI-generated invoice template artifacts
Body: CSS clamp() font obfuscation
Body: CSS Hidden text via clip-path
Body: CSS Hidden text via table-column
Body: CSS zero-value calc() obfuscation
Body: CVE-2026-42897 Exchange OWA stored XSS
Body: Fake secure email portal with HTML obfuscation
Body HTML: Comment with 24-character hex token
Body HTML: Recipient SLD in HTML class
Body: HTML whitespace stuffing with short initial message
Body: Invisible Unicode obfuscation student loan callback phishing
Body: Suspicious table template fingerprint
Body: Yellow highlighted text markers
Brand impersonation: Adobe Sign with suspicious indicators
Brand impersonation: Aramco
Brand impersonation: Binance
Brand impersonation: Fake DocuSign HTML table not linking to DocuSign domains
Brand impersonation: Figma with malicious document access overlay
Brand impersonation: File sharing notification with template artifacts
Brand impersonation: Greetings Island
Brand impersonation: Microsoft logo image linking to free file host
Brand impersonation: Microsoft logo in HTML with fake quarantine release notification
Brand impersonation: Microsoft Teams invitation
Brand impersonation: Paperless Post
Brand impersonation: Zoom
Brand impersonation: Zoom via HTML styling
Callback phishing: AOL senders with suspicious HTML template or PDF attachment
Callback phishing: Zero-width character obfuscation from freemail sender
Canva design with suspicious embedded link
Credential phishing: Blue button styled link with file-sharing template artifacts
Credential phishing: Personalized document signing request
Credential phishing: Suspicious e-sign agreement document notification
Credential Phishing: W-2 lure with inline SVG Windows logo
Credential theft: Gophish abuse with hidden tracking image
Credential theft: JavaScript date manipulation in HTML body
CVE-2023-5631 - Roundcube Webmail XSS via crafted SVG
Evasion: Hidden content divs from freemail sender
Evasion: Hidden text using CSS-obscured HTML option labels
Fake Zoho Sign template abuse
Google presentation open redirect phishing
Google share notification with suspicious comments
HTML: Bidirectional (BIDI) HTML override with right to left obfuscation
HTML content with print styling and credential theft language
HTML smuggling with atob in message body
HTML: Template placeholders or recipient email in element class attributes
Image as content with a link to an open redirect
Impersonation: Chrome Web Store policy