Attack Type: Credential Phishing

Credential phishing attacks are designed to steal your login information by tricking you into entering it on fake login pages. These emails impersonate trusted services like Microsoft 365, Google Workspace, or banking sites, using urgent phrases like “verify your account,” “prevent suspension,” or “view shared document” to push you into clicking.
Once you click the link, it leads to a fake login page that looks convincing. If you enter your credentials, the attacker captures them immediately. Common examples include phishing emails pretending to be DocuSign requests, Dropbox links, or HR file shares—things that feel routine but create a false sense of urgency.
Attackers often use real platforms like Microsoft Forms, Google Forms, or compromised websites to host these fake login pages, making the links appear legitimate and harder for security tools to catch. The damage doesn’t stop at just stealing your login. Once attackers gain access, they can move through your organization, steal sensitive data, send internal phishing emails, or even launch a ransomware attack.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Observed IOC: Malicious sender email addresses
1d ago
May 29th, 2026
Sublime Security
Credential phishing: Engaging language and other indicators (untrusted sender)
1d ago
May 29th, 2026
Sublime Security
Brand impersonation: Meta and subsidiaries
1d ago
May 29th, 2026
Sublime Security
Body: HTML whitespace stuffing with short initial message
1d ago
May 29th, 2026
Sublime Security
Attachment: ICS calendar file with suspicious product identifier
1d ago
May 29th, 2026
Sublime Security
Impersonation Link: Cloud branding service with credential theft language
1d ago
May 29th, 2026
Sublime Security
Credential phishing: Suspicious e-sign agreement document notification
1d ago
May 29th, 2026
Sublime Security
Attachment: Compensation-themed DOCX with QR code credential theft
1d ago
May 29th, 2026
Sublime Security
Link: Numeric IP obfuscation in URL
2d ago
May 28th, 2026
Sublime Security
Credential phishing: Fake storage alerts (unsolicited)
2d ago
May 28th, 2026
Sublime Security
Credential phishing: AWS Lambda URL with recipient targeting
2d ago
May 28th, 2026
Sublime Security
Link: Self-sender credential theft with configuration placeholder
3d ago
May 27th, 2026
Sublime Security
Service abuse: Google OAuth with suspicious redirect destination
3d ago
May 27th, 2026
Sublime Security
Brand impersonation: Figma with malicious document access overlay
3d ago
May 27th, 2026
Sublime Security
Observed IOC: Malicious root domains in body links
3d ago
May 27th, 2026
Sublime Security
Observed IOC: Malicious sender domains
3d ago
May 27th, 2026
Sublime Security
Brand impersonation: DHL
4d ago
May 26th, 2026
Sublime Security
Service abuse: Square marketing with suspicious QR code
4d ago
May 26th, 2026
Sublime Security
Brand Impersonation: Procore
4d ago
May 26th, 2026
Sublime Security
Brand impersonation: Dashlane
4d ago
May 26th, 2026
Sublime Security