Attachment: Calendar invite from recently registered domain
Attachment: DocuSign impersonation via PDF linking to new domain
Attachment: Embedded MSG file with payment lure and newly registered domain
Attachment: ICS calendar invite with bid/RFP lure and suspicious link
Attachment: ICS calendar invite with financial lure and suspicious link
Attachment: ICS calendar with suspicious link Leading to minimal JS landing page
Attachment: ICS file with credential theft indicators
Attachment: ICS file with links to newly registered domains
Attachment: ICS voicemail lure with suspicious link
Attachment: Legal themed message or PDF with suspicious indicators
Attachment: PDF with multistage landing - ClickUp abuse
BEC: Financial fraud from newly registered sender domain
BEC/Fraud: Urgent language and suspicious sending/infrastructure patterns
BEC: Wealth management lure from newly registered domain
Brand impersonation: Anthropic/Claude with newly registered domain
Brand impersonation: Microsoft fake sign-in alert
Brand Impersonation: OpenAI with ChatGPT Ads lure
Brand impersonation: SharePoint PDF attachment with credential theft language
Brand impersonation: Silicon Valley Bank
Brand impersonation: Stripe notification
Callback phishing: Branded invoice from sender/reply-to domain less than 30 days old
Credential phishing: Fake security alert from newly registered domain
Fraudulent order confirmation/shipping notification from Chinese sender domain
Generic service abuse from newly registered domain
Impersonation: Suspected supplier impersonation with suspicious content
Link: Abused Adobe Express
Link: Commonly Abused Web Service redirecting to ZIP file
Link: Cryptocurrency fraud with suspicious links
Link: Document-themed link to newly registered domain
Link: Fake video link from newly registered domain
Link: Financial account issue with suspicious indicators
Link: Google Firebase dynamic link that redirects to new domain (<7 days old)
Link: Multistage landing - Abused Adobe frame.io
Link: Multistage landing - Abused Docusign
Link: Multistage landing - Abused Google Drive
Link: Multistage landing - ClickUp abuse
Link: Multistage landing - Published Google Doc
Link: Newly registered domain in reference lure
Link: Newly registered suspicious domain with single-character HTML filename
Link: Observed URL pattern with specific domain registrar
Link: Recently registered .vu domain in lure
Link: Romance/Sexual Language With Suspicious Link
Link: Tax document lure Portuguese/Spanish with suspicious domains
New link domain (<=10d) from untrusted sender
Newly registered sender or reply-to domain with newly registered linked domain
New sender domain (<=10d) from untrusted sender
Open redirect: Recipient address embedded in redirect URL pointing to newly registered domain
Recruitee Infrastructure Abuse
Service abuse: Adobe message from newly registered domain
Service abuse: AppSheet infrastructure with suspicious indicators