Body: HTML whitespace stuffing with short initial message
Body: Invisible Unicode obfuscation student loan callback phishing
Body: Suspicious table template fingerprint
Body: Yellow highlighted text markers
Brand impersonation: Adobe Sign with suspicious indicators
Brand impersonation: Aramco
Brand impersonation: Binance
Brand impersonation: Fake DocuSign HTML table not linking to DocuSign domains
Brand impersonation: Figma with malicious document access overlay
Brand impersonation: File sharing notification with template artifacts
Brand impersonation: Microsoft logo in HTML with fake quarantine release notification
Brand impersonation: Microsoft Teams invitation
Brand impersonation: Paperless Post
Brand impersonation: Zoom
Brand impersonation: Zoom via HTML styling
Callback phishing: AOL senders with suspicious HTML template or PDF attachment
Canva design with suspicious embedded link
Credential phishing: Blue button styled link with file-sharing template artifacts
Credential phishing: Suspicious e-sign agreement document notification
Credential Phishing: W-2 lure with inline SVG Windows logo
Credential theft: Gophish abuse with hidden tracking image
Credential theft: JavaScript date manipulation in HTML body
CVE-2023-5631 - Roundcube Webmail XSS via crafted SVG
Evasion: Hidden content divs from freemail sender
Fake Zoho Sign template abuse
Google presentation open redirect phishing
Google share notification with suspicious comments
HTML: Bidirectional (BIDI) HTML override with right to left obfuscation
HTML content with print styling and credential theft language
HTML smuggling with atob in message body
HTML: Template placeholders or recipient email in element class attributes
Image as content with a link to an open redirect
Impersonation: Chrome Web Store policy
Impersonation: Fake product discount promotion
Inline image as message with attachment or link
Link: Abused Adobe Express
Link: Apple App Store link to apps impersonating AI adveristing
Link: chatbot.page platform abuse
Link: Common hidden directory observed
Link: Credential harvesting with excess padding evasion
Link: Credential theft with invisible Unicode character in page title from unsolicited sender
Link: Fake secure message notification template
Link: File sharing pretext with suspicious body and link
Link: Multistage landing - Abused Adobe frame.io
Link: Multistage landing - Abused Docusign
Link: Multistage landing - Abused Google Drive
Link: Multistage landing - JotForm abuse
Link: Multistage landing - Microsoft Forms abuse
Link: Multistage landing - Scribd document
Link: PDF display text with fake copyright claim template