Display Name Emoji with Financial Symbols
EML attachment with credential theft language (unknown sender)
Encrypted Microsoft Office files from untrusted sender
Evasion: Hidden content divs from freemail sender
Fake shipping notification with suspicious language
Fake thread with suspicious indicators
Fake warning banner using confusable characters
Fake Zoho Sign template abuse
Fake Zoom meeting invite with suspicious link
Generic service abuse from newly registered domain
Google Drive direct download link from unsolicited sender
Google presentation open redirect phishing
Google services using g.co shortlinks
Hardbacon infrastructure abuse
Headers: Fake in-reply-to with wildcard sender and missing thread context
Headers: Invalid recipient domain with mismatched reply-to from new sender
Headers: iOS/iPadOS mailer with invalid build number
Headers: Outlook Express mailer
Headers: risky-recover-production message ID
Headers: Self-sender using Microsoft CompAuth bypass with credential theft content
HR impersonation via e-sign agreement comment
HTML: Bidirectional (BIDI) HTML override with right to left obfuscation
HTML content with print styling and credential theft language
HTML smuggling containing recipient email address
HTML: Template placeholders or recipient email in element class attributes
Image as content with a link to an open redirect
Impersonation: SharePoint reply header anomaly
Impersonation: Suspected supplier impersonation with suspicious content
Inbound message from popular service via newly observed distribution list
Inline image as message with attachment or link
Issuu document with suspicious embedded link
Link: 9WOLF phishkit initial landing URI
Link: Abused Adobe Express
Link: Adobe share from unsolicited sender
Link: Adobe share with suspicious indicators
Link: Apple App Store malicious ad manager themed apps from free email provider
Link: Apple TestFlight from suspicious sender
Link: Base64 encoded recipient address in URL fragment with hex subdomain
Link: Base64 encoded recipient address in URL fragment with subject hash
Link: BEC with newly registered domains and financial keywords
Link: Common hidden directory observed
Link: Commonly Abused Web Service redirecting to ZIP file
Link: Concatenated display text concealing duplicate URLs with PDF reference
Link: Credential harvesting with excess padding evasion
Link: Credential phishing link with undisclosed recipients
Link: Credential theft with Cloudflare tunnel and recipient targeting
Link: Credential theft with invisible Unicode character in page title from unsolicited sender
Link: Cryptocurrency fraud with suspicious links
Link: CVE-2024-21413 Microsoft Outlook Remote Code Execution Vulnerability
Link: Direct download of executable file