Attachment: PDF with link to zip containing a wsf file
Attachment: PDF with multistage landing - ClickUp abuse
Attachment: PDF with recipient email in link
Attachment: PDF with self-service platform links with self sender or blank recipients
Attachment: PDF with suspicious language and redirect to suspicious file type
Attachment: PDF with suspicious link and action-oriented language
Attachment: PDF with View RFP Document lure with external link
Attachment: QR code with credential phishing indicators
Attachment: QR code with encoded recipient targeting and redirect indicators
Attachment: QR code with recipient targeting and special characters
Attachment: QR code with suspicious URL patterns in EML file
Attachment: Romance scam with image lure and advance-fee or suspicious link indicators
Attachment: RTF file with suspicious link
Attachment: RTF with link to free-hosted Cloudflare Pages
Attachment: Single-page PDF with S3-hosted HTML link
Attachment: Small text file with link containing recipient email address
Attachment: Word document with hyperlink and fraud language
BEC/Fraud: Self-addressed reply with unrelated link in ongoing thread
Body: CSS clamp() font obfuscation
Body: Fake secure email portal with HTML obfuscation
Brand impersonation: AliExpress
Brand impersonation: Bids & Tenders
Brand impersonation: Chase bank with credential phishing indicators
Brand impersonation: Cloud services with credential theft intent
Brand impersonation: Coinbase with suspicious links
Brand impersonation: DocuSign
Brand impersonation: DocuSign PDF attachment with suspicious link
Brand impersonation: Fake DocuSign HTML table not linking to DocuSign domains
Brand impersonation: Fake Fax
Brand impersonation: Figma with malicious document access overlay
Brand Impersonation: Gemini Trust Company
Brand impersonation: Google Careers
Brand impersonation: Google Drive fake file share
Brand impersonation: Google fake sign-in warning
Brand impersonation: Google Meet with malicious link
Brand impersonation: Google Workspace alert notification
Brand impersonation: Government / Tax Authority document lure
Brand impersonation: LastPass
Brand impersonation: Microsoft logo image linking to free file host
Brand impersonation: Microsoft logo or suspicious language with open redirect
Brand impersonation: Microsoft Planner with suspicious link
Brand impersonation: Microsoft Teams invitation
Brand impersonation: Microsoft with low reputation links
Brand impersonation: Navan
Brand impersonation: Paperless Post
Brand impersonation: Proofpoint secure messaging without legitimate indicators
Brand impersonation: Purdue ePlanroom with suspicious links
Brand impersonation: Robinhood
Brand impersonation: Sharepoint fake file share
Brand impersonation: SharePoint PDF attachment with credential theft language