High Severity

Link: Observed URL path (lht) with recipient email address

Description

This rule flags inbound messages where a link in the body contains the recipient's own email address appended to the URL path (e.g. after '/&lht='), a technique used to personalize or validate tracking links. The matched samples consistently use a fake missed voicecall/voicemail notification lure with obfuscated, zero-width characters in the subject line and spoofed sender domains, directing recipients to a credential-harvesting page tailored to their address.

References

No references.

Sublime Security
Created Oct 6th, 2026 • Last updated Oct 6th, 2026
Source
type.inbound
and recipients.to[0].email.domain.valid
and any(body.links,
        strings.iends_with(.href_url.path,
                           strings.concat('/&lht=',
                                          recipients.to[0].email.email
                           )
        )
)
MQL Rule Console
•Docs•Learning Labs

Playground

Test against your own EMLs or sample data.

Share

Post about this on your socials.

Get Started. Today.

Managed or self-managed. No MX changes.

Deploy and integrate a free Sublime instance in minutes.
Get Started