Attack Type: Credential Phishing

Credential phishing attacks are designed to steal your login information by tricking you into entering it on fake login pages. These emails impersonate trusted services like Microsoft 365, Google Workspace, or banking sites, using urgent phrases like “verify your account,” “prevent suspension,” or “view shared document” to push you into clicking.
Once you click the link, it leads to a fake login page that looks convincing. If you enter your credentials, the attacker captures them immediately. Common examples include phishing emails pretending to be DocuSign requests, Dropbox links, or HR file shares—things that feel routine but create a false sense of urgency.
Attackers often use real platforms like Microsoft Forms, Google Forms, or compromised websites to host these fake login pages, making the links appear legitimate and harder for security tools to catch. The damage doesn’t stop at just stealing your login. Once attackers gain access, they can move through your organization, steal sensitive data, send internal phishing emails, or even launch a ransomware attack.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
URL with Unicode U+2044 (⁄) or U+2215 (∕) characters
13h ago
Aug 6th, 2026
@delivr_to
Observed IOC: Malicious sender email addresses
13h ago
Aug 6th, 2026
Sublime Security
Brand impersonation: SoFi
13h ago
Aug 6th, 2026
Sublime Security
Link: Numeric IP obfuscation in URL
13h ago
Aug 6th, 2026
Sublime Security
Brand impersonation: Punchbowl
14h ago
Aug 6th, 2026
Sublime Security
Credential phishing content and link (untrusted sender)
22h ago
Aug 6th, 2026
Sublime Security
Brand impersonation: Meta and subsidiaries
22h ago
Aug 6th, 2026
Sublime Security
Brand impersonation: Amazon
23h ago
Aug 6th, 2026
Sublime Security
Brand impersonation: Cloud services with credential theft intent
23h ago
Aug 6th, 2026
Sublime Security
Observed IOC: Mail transiting OFAC-sanctioned bulletproof host Aeza Group
2d ago
Aug 5th, 2026
Sublime Security
Observed IOC: Mail transiting bulletproof host - SmartApe
2d ago
Aug 5th, 2026
Sublime Security
Service abuse: Evernote link
2d ago
Aug 5th, 2026
Sublime Security
Body: CSS Hidden text via clip-path
2d ago
Aug 5th, 2026
Sublime Security
Body: CSS zero-value calc() obfuscation
2d ago
Aug 5th, 2026
Sublime Security
Service abuse: Wufoo credential theft
2d ago
Aug 5th, 2026
Sublime Security
Link: Mismatched free file host links with document lure
2d ago
Aug 5th, 2026
Sublime Security
VIP Impersonation via Google Group relay with suspicious indicators
2d ago
Aug 5th, 2026
Sublime Security
HTML: Template placeholders or recipient email in element class attributes
2d ago
Aug 5th, 2026
Sublime Security
AnonymousFox indicators
2d ago
Aug 5th, 2026
Sublime Security
Brand impersonation: Microsoft with embedded logo and credential theft language
3d ago
Aug 4th, 2026
Sublime Security