Tactic or Technique: Encryption

Attackers use encryption to hide malicious content, avoid detection, and control when and how their payloads are delivered. By encrypting files or obfuscating code, they can slip past email security tools that scan attachments and message content for known threats.
You might receive a password-protected ZIP or PDF that contains malware or a phishing link. Some attacks use encrypted HTML files that only show a fake login page after they're opened. Others use base64 or similar encoding to hide malicious code inside files that look harmless at first glance.
In many cases, the password to unlock the file is included in the email, sent in a follow-up message, or shared over another channel. Some attackers also encrypt stolen data before sending it out to avoid detection on the way out.
This tactic gives attackers more control and makes it harder for you—and your security tools—to see what’s really happening. It's often used in the early stages of malware delivery, data theft, or ransomware attacks.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Encrypted Microsoft Office files from untrusted sender
8d ago
Sep 28th, 2026
Sublime Security
Attachment: Encrypted PDF with credential theft body
11d ago
Sep 25th, 2026
Sublime Security
Link to auto-downloaded DMG in encrypted zip
13d ago
Sep 23rd, 2026
Sublime Security
Attachment: PDF with recipient email in link
14d ago
Sep 22nd, 2026
Sublime Security
Link: Suspicious Family fragment parameter with encoded recipient data
14d ago
Sep 22nd, 2026
Sublime Security
Link: Hex-encoded recipient email in URL fragment
20d ago
Sep 16th, 2026
Sublime Security
Attachment: Encrypted PDF with credential theft language in EML
1mo ago
Sep 4th, 2026
Sublime Security
Link: Double base64-encoded URL path
1mo ago
Aug 24th, 2026
Sublime Security
Attachment: Identity Confirmation With Document Unlock Code
2mo ago
Jul 28th, 2026
Sublime Security
Attachment: Encrypted PDF With Credential Harvesting Indicators
4mo ago
Jun 5th, 2026
Sublime Security
Attachment with unscannable encrypted zip
5mo ago
Apr 30th, 2026
Sublime Security
Adobe branded PDF file linking to a password-protected file from untrusted sender
5mo ago
Apr 29th, 2026
Sublime Security
Attachment: Encrypted ZIP containing VHDX file
6mo ago
Apr 3rd, 2026
Sublime Security
Attachment: PDF with password in filename matching body text
7mo ago
Feb 19th, 2026
Sublime Security
Attachment: Password-protected PDF with fake document indicators
8mo ago
Jan 21st, 2026
Sublime Security
Link: Excessive URL rewrite encoders
8mo ago
Jan 21st, 2026
Sublime Security
Attachment: HTML smuggling with RC4 decryption
8mo ago
Jan 12th, 2026
Sublime Security
Attachment: HTML smuggling with ROT13
8mo ago
Jan 12th, 2026
@Kyle_Parrish_
Link: Base64 encoded recipient address in URL fragment with subject hash
8mo ago
Jan 12th, 2026
Sublime Security
Attachment: HTML smuggling with excessive line break obfuscation
8mo ago
Jan 12th, 2026
Sublime Security