Attack Type: Credential Phishing

Credential phishing attacks are designed to steal your login information by tricking you into entering it on fake login pages. These emails impersonate trusted services like Microsoft 365, Google Workspace, or banking sites, using urgent phrases like “verify your account,” “prevent suspension,” or “view shared document” to push you into clicking.
Once you click the link, it leads to a fake login page that looks convincing. If you enter your credentials, the attacker captures them immediately. Common examples include phishing emails pretending to be DocuSign requests, Dropbox links, or HR file shares—things that feel routine but create a false sense of urgency.
Attackers often use real platforms like Microsoft Forms, Google Forms, or compromised websites to host these fake login pages, making the links appear legitimate and harder for security tools to catch. The damage doesn’t stop at just stealing your login. Once attackers gain access, they can move through your organization, steal sensitive data, send internal phishing emails, or even launch a ransomware attack.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Observed IOC: Malicious sender email addresses
3d ago
Jun 19th, 2026
Sublime Security
Observed IOC: Malicious sender domains
3d ago
Jun 19th, 2026
Sublime Security
Service abuse: DocSend share from an unsolicited reply-to address
4d ago
Jun 18th, 2026
Sublime Security
Body: Fake secure email portal with HTML obfuscation
4d ago
Jun 18th, 2026
Sublime Security
Link: Mamba 2FA phishing kit
4d ago
Jun 18th, 2026
Sublime Security
Brand impersonation: Cloud services with credential theft intent
4d ago
Jun 18th, 2026
Sublime Security
Service abuse: Google Firebase sender address with suspicious content
4d ago
Jun 18th, 2026
Sublime Security
Credential phishing: Fake storage alerts (unsolicited)
4d ago
Jun 18th, 2026
Sublime Security
Brand impersonation: Bids & Tenders
5d ago
Jun 17th, 2026
Sublime Security
Service abuse: Outlook Groups with Google Sites link and evasion tag
5d ago
Jun 17th, 2026
Sublime Security
Brand impersonation: Microsoft
5d ago
Jun 17th, 2026
@amitchell516
Evasion: Hidden content divs from freemail sender
5d ago
Jun 17th, 2026
Sublime Security
Attachment: PDF with a suspicious string and single URL
5d ago
Jun 17th, 2026
Sublime Security
Brand impersonation: Quickbooks
5d ago
Jun 17th, 2026
Sublime Security
Attachment: PDF Object Hash associated with fake Canada Revenue Agency documents
5d ago
Jun 17th, 2026
Sublime Security
Attachment: Encrypted PDF with credential theft body
5d ago
Jun 17th, 2026
Sublime Security
Brand impersonation: Fake Fax
5d ago
Jun 17th, 2026
Sublime Security
Fake thread with suspicious indicators
5d ago
Jun 17th, 2026
Sublime Security
Brand impersonation: Survey request with credential theft indicators
5d ago
Jun 17th, 2026
Sublime Security
Self-impersonation: Sender matches recipient with bolded name and suspicious link
6d ago
Jun 16th, 2026
Sublime Security