Job scam (unsolicited sender)
Job scam with specific salary pattern
Link abuse: Self-service creation platform link with suspicious recipient behavior
Link: Base64 encoded recipient address in URL fragment with subject hash
Link: BEC with newly registered domains and financial keywords
Link: Credential phishing link with undisclosed recipients
Link: Credential phishing traversing Russian infrastructure
Link: Credential phishing via WordPress
Link: Cryptocurrency fraud with suspicious links
Link: Direct link to riddle.com hosted showcase
Link: Direct link to Zoom Docs from non-Zoom sender
Link: Display text matches subject line
Link: Executable file download with suspicious message content
Link: Fake RFP/bid reference number lure
Link: File sharing impersonation with suspicious language and sending patterns
Link: Free file hosting with undisclosed recipients
Link: Free subdomain host with undisclosed recipients
Link: Generic financial document with proceedural timeline template
Link: Intuit link abuse with file share context
Link: Invalid reply-to with recipient details in subject, body, and encoded link
Link: Microsoft protected message with suspicious recipient patterns
Link: Mismatched Shopify template button href
Link: Multistage landing - Abused Adobe Acrobat hosted PDF
Link: Multistage landing - Ludus presentation
Link: .onion From Unsolicited Sender
Link: PDF filename impersonation with credential theft language
Link: Personalized URL with recipient address on commonly abused web service
Link: Personal SharePoint with invalid recipients and credential theft language
Link: Recipient domain in URL path
Link: Referrer anonymization service from untrusted sender
Link: Romance/Sexual Language With Suspicious Link
Link: Self-sender credential theft with configuration placeholder
Link: Self-sender with sender org in subject and credential theft indicator
Link: Self-sent message with quarterly document review request
Link: Self-sent PDF lure with subject correlation
Link: SharePoint OneNote or PDF link with self sender behavior
Link: Shortened URL with fragment matching subject
Link: Single character path with credential theft body and self sender behavior or invalid recipient
Link: Squarespace infrastructure abuse
Link: Suspicious Sharepoint folder share
Link: Suspicious wp-admin path from mismatched sender domain
Link: Uncommon SharePoint document type with sender's display name
macOS malware: Compiled AppleScript with document double-extension
Mass campaign: Cross Site Scripting (XSS) attempt
Mass campaign: recipient address in subject, body, and link (untrusted sender)
Message traversed multiple onmicrosoft.com tenants
Microsoft infrastructure abuse with suspicious patterns
Newly registered sender or reply-to domain with newly registered linked domain
Observed IOC: Mail transiting bulletproof host - SmartApe
Observed IOC: Mail transiting OFAC-sanctioned bulletproof host Aeza Group