Attachment: Small text file with link containing recipient email address
Attachment: Suspicious employee policy update document lure
Attachment: Suspicious PDF created with headless browser
Attachment: SVG files with evasion elements
Attachment: SVG file with HTML entity encoded href attributes
Attachment: SVG file with hyperlinks and cursor styling
Attachment: TAR file with RAR type
Attachment: Web files with suspicious comments
Attachment: WinRAR CVE-2025-8088 exploitation
Attachment with encrypted zip (unsolicited)
Attachment with macro calling executable
Attachment with unscannable encrypted zip
Attachment: Word document with hyperlink and fraud language
Attachment: XLSX file with suspicious print titles metadata
Attachment: ZIP containing Office binary with embedded DLL
Attachment: ZIP filename mismatch
Attachment: ZIP file with CVE-2026-0866 exploit
BEC/Fraud: Reply-chain manipulation with urgent keywords and self-reply
BEC with unusual reply-to or return-path mismatch
Benefits enrollment impersonation
Body: CSS clamp() font obfuscation
Body: CSS Hidden text via clip-path
Body: CSS Hidden text via table-column
Body: CSS zero-value calc() obfuscation
Body: CVE-2026-42897 Exchange OWA stored XSS
Body: Embedded email headers indicative of thread hijacking/abuse
Body: Fake secure email portal with HTML obfuscation
Body HTML: Comment with 24-character hex token
Body HTML: Recipient SLD in HTML class
Body: HTML whitespace stuffing with short initial message
Body: Invisible Unicode obfuscation student loan callback phishing
Body: Suspicious date format
Body: Suspicious table template fingerprint
Body: Yellow highlighted text markers
Brand impersonation: Coinbase with suspicious links
Brand impersonation: DocuSign with embedded QR code
Brand impersonation: File sharing notification with template artifacts
Brand impersonation: Microsoft logo in HTML with fake quarantine release notification
Brand impersonation: Microsoft Planner with suspicious link
Brand impersonation: QuickBooks notification from Intuit themed company name
Brand Impersonation: ShareFile
Brand impersonation: SharePoint PDF attachment with credential theft language
Brand impersonation: Stripe notification
Brand impersonation: Zoom
Business Email Compromise (BEC) attempt with masked recipients and reply-to mismatch (unsolicited)
Callback phishing: Social Security Administration fraud
Callback phishing: SumUp infrastructure abuse
Callback phishing via Adobe Sign comment
Callback phishing via calendar invite
Callback phishing via DocuSign comment