Description

Detects suspicious content in Zoom Events notifications that contain credential theft language and links to file hosting sites.

Sublime Security
Created Jun 23rd, 2025 • Last updated Jul 8th, 2026
Source
type.inbound
and sender.email.email == "noreply-zoomevents@zoom.us"
and (headers.auth_summary.spf.pass or headers.auth_summary.dmarc.pass)

// extract the actor controlled content from the email body (excluding the
// static Zoom copyright/unsubscribe footer) and pass it to NLU
and any(html.xpath(body.html,
                   "//div[@class='eb-content css-1l7xmti']//td[@data-dynamic-style-background-color='email.bodyColor.color' and contains(@style, 'background-color: rgb(255, 255, 255)')]/*[not(.//*[contains(text(), 'Copyright') or contains(text(), 'unsubscribe')])]"
        ).nodes,
        any(ml.nlu_classifier(.display_text).intents,
            .name == "cred_theft" and .confidence != "low"
        )
)
MQL Rule Console
DocsLearning Labs

Playground

Test against your own EMLs or sample data.

Share

Post about this on your socials.

Get Started. Today.

Managed or self-managed. No MX changes.

Deploy and integrate a free Sublime instance in minutes.
Get Started