Medium Severity

Attachment: Mobileconfig profile with mismatched embedded email

Description

Detects inbound messages with a mobileconfig attachment containing an embedded email address whose domain differs from the sender's domain and does not match any known sender or recipient address. These crafted files are used as a lure to trick recipients into installing a bogus update, often paired with payment or account-themed subject lines and disposable or spoofed sender domains.

References

No references.

Sublime Security
Created Sep 29th, 2026 • Last updated Sep 29th, 2026
Source
type.inbound
and any(attachments,
        .file_extension == "mobileconfig"
        and any(regex.iextract(file.parse_text(.).text,
                               '<string>\s*(?P<email>[^\s]+@[^\s]+)\s*[^\<]+\</string>'
                ),
                strings.parse_email(.named_groups["email"]).domain.root_domain != sender.email.domain.root_domain
                and strings.parse_email(.named_groups["email"]).email not in map(recipients.to,
                                                                                 .email.email
                )
                and strings.parse_email(.named_groups["email"]).email not in $recipient_emails
                and strings.parse_email(.named_groups["email"]).email not in $sender_emails
        )
)
MQL Rule Console
•Docs•Learning Labs

Playground

Test against your own EMLs or sample data.

Share

Post about this on your socials.

Get Started. Today.

Managed or self-managed. No MX changes.

Deploy and integrate a free Sublime instance in minutes.
Get Started