Impersonation: Fake product discount promotion
Impersonation: SAM/SBA federal registration
Inline image as message with attachment or link
Link: Abused Adobe Express
Link: Apple App Store link to apps impersonating AI adveristing
Link: chatbot.page platform abuse
Link: Common hidden directory observed
Link: Credential harvesting with excess padding evasion
Link: Credential theft with invisible Unicode character in page title from unsolicited sender
Link: Fake secure message notification template
Link: Fake webmail hosting
Link: File sharing pretext with suspicious body and link
Link: Gmail phishkit with suspicious recipient
Link: Mismatched Shopify template button href
Link: Multistage landing - Abused Adobe frame.io
Link: Multistage landing - Abused Docusign
Link: Multistage landing - Abused Google Drive
Link: Multistage landing - JotForm abuse
Link: Multistage landing - Microsoft Forms abuse
Link: Multistage landing - Scribd document
Link: PDF display text with fake copyright claim template
Link: RTL text reversal with recipient email in URL
Link: Self-sent PDF lure with subject correlation
Link: Suspicious HTML structure with subject mirrored in body and single link
Link: Suspicious Loom HTML file path
Link: Suspicious recipient with timeout redirect
Link: Suspicious Sharepoint folder share
Link: Suspicious single-domain link with suspicious path and financial lure indicators
Link: Tycoon2FA phishing kit (non-exhaustive)
Link: Uncommon SharePoint document type with sender's display name
Link: URL fragmented by hidden spans
Link: URL scheme obfuscation via split HTML anchors
Low reputation link to auto-downloaded HTML file with smuggling indicators
Open redirect: Shibboleth SSO Logout Return Parameter
Outlook hyperlink bypass: left-to-right mark (LRM) in base HTML tag
Potential prompt injection attack in body HTML
Request for Quote or Purchase (RFQ|RFP) with HTML smuggling attachment
Self-impersonation: Sender matches recipient with bolded name and suspicious link
Service abuse: Adobe Creative Cloud share from an unsolicited sender address
Service abuse: Amazon invitation with suspected callback phishing
Service abuse: Apple TestFlight with suspicious developer reference
Service abuse: EventCreate links to newly registered domains
Service abuse: Google Firebase sender address with suspicious content
Service abuse: HelloSign from an unsolicited sender address
Service abuse: HungerRush domain with SendGrid tracking targeting ProtonMail
Service abuse: Meetup.com redirect with brand impersonation
Service abuse: Oracle Cloud Workflow callback scam
Service abuse: Soundestlink.com Microsoft impersonation
Service abuse: Soundestlink redirect with suspicious indicators
Service abuse: Substack credential theft with confusable characters and branded button redirects