Brand impersonation: USPS
Brand impersonation: Wells Fargo
Brand impersonation: Zoom
Brand impersonation: Zoom via HTML styling
Callback phishing: AOL senders with suspicious HTML template or PDF attachment
Callback phishing in body or attachment (untrusted sender)
Callback phishing: SumUp infrastructure abuse
Callback phishing via Apple ID display name abuse
Callback phishing via Intuit service abuse
Callback phishing via Zelle Service Abuse
Canva infrastructure abuse
Compensation review with QR code in attached EML
Credential phishing: Blue button styled link with file-sharing template artifacts
Credential phishing: Engaging language with IPFS link
Credential phishing: Fake password expiration from new and unsolicited sender
Credential phishing: Financial lure via ActiveCampaign infrastructure
Credential phishing link (unknown sender)
Credential phishing: Suspicious e-sign agreement document notification
Credential Phishing: W-2 lure with inline SVG Windows logo
Credential theft: Gophish abuse with hidden tracking image
CVE-2023-5631 - Roundcube Webmail XSS via crafted SVG
Deceptive Dropbox mention
EML attachment with credential theft language (unknown sender)
Evasion: Hidden content divs from freemail sender
Extortion / sextortion (untrusted sender)
Fake message thread - Untrusted sender with a mismatched freemail reply-to address
Fake shipping notification with link to free file hosting
Fake thread with suspicious indicators
Fake voicemail notification (untrusted sender)
Fake Zoho Sign template abuse
Google share notification with suspicious comments
HTML: Bidirectional (BIDI) HTML override with right to left obfuscation
HTML content with print styling and credential theft language
HTML smuggling with atob in message body
Image as content with a link to an open redirect
Impersonation: Chrome Web Store policy
Impersonation: Fake Gmail attachment
Impersonation: SharePoint reply header anomaly
Inline image as message with attachment or link
Link: Adobe share with suspicious indicators
Link: Credential harvesting with excess padding evasion
Link: Display text with excessive right-to-left mark characters
Link: File sharing pretext with suspicious body and link
Link: Microsoft impersonation using hosted png with suspicious link
Link: PDF and financial display text to free file host
Link: PDF display text with fake copyright claim template
Link: Self-sender with sender org in subject and credential theft indicator
Link: Self-sent PDF lure with subject correlation
Link: SharePoint OneNote or PDF link with self sender behavior