Tactic or Technique: Evasion

Evasion techniques help attackers sneak past email security filters by hiding or disguising malicious content. These tactics are designed to fool both traditional scanners and newer AI-based systems by changing how the message is structured or displayed.
You might see phishing content buried under blocks of harmless-looking text, or important details shown as images so they can't be scanned. Some messages break up keywords using hidden HTML or use misspelled words and lookalike characters to trick you into missing the signs.
More advanced versions use JavaScript that reveals the payload only after the message has passed through security checks. Others try to confuse AI systems with prompt injection or strange formatting.
These techniques create gaps in protection and give attackers a better chance of reaching your inbox. Spotting them early is key. The more familiar you are with how these tricks work, the easier it is to catch them before they do damage.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Link: Numeric IP obfuscation in URL
13h ago
Aug 6th, 2026
Sublime Security
URL with Unicode U+2044 (⁄) or U+2215 (∕) characters
13h ago
Aug 6th, 2026
@delivr_to
Spam: Fake photo share
22h ago
Aug 6th, 2026
Sublime Security
Observed IOC: Mail transiting bulletproof host - SmartApe
2d ago
Aug 5th, 2026
Sublime Security
Observed IOC: Mail transiting OFAC-sanctioned bulletproof host Aeza Group
2d ago
Aug 5th, 2026
Sublime Security
Callback phishing: Zero-width character obfuscation from freemail sender
2d ago
Aug 5th, 2026
Sublime Security
Body: CSS Hidden text via clip-path
2d ago
Aug 5th, 2026
Sublime Security
Body: CSS zero-value calc() obfuscation
2d ago
Aug 5th, 2026
Sublime Security
Attachment: Callback phishing solicitation via text-based file
2d ago
Aug 5th, 2026
Sublime Security
HTML: Template placeholders or recipient email in element class attributes
2d ago
Aug 5th, 2026
Sublime Security
VIP Impersonation via Google Group relay with suspicious indicators
2d ago
Aug 5th, 2026
Sublime Security
Spam: Cold outreach from Cloudflare-hosted newly registered domain
3d ago
Aug 4th, 2026
Sublime Security
Link: Suspicious recipient with timeout redirect
3d ago
Aug 4th, 2026
Sublime Security
Link: Unformatted template with literal placeholder in mailto link
4d ago
Aug 3rd, 2026
Sublime Security
Link: Unicode character obfuscation in display name with base64-encoded URL fragment
4d ago
Aug 3rd, 2026
Sublime Security
Service abuse: Adobe message from newly registered domain
7d ago
Jul 31st, 2026
Sublime Security
Body: HTML whitespace stuffing with short initial message
7d ago
Jul 31st, 2026
Sublime Security
Body: CSS clamp() font obfuscation with IP-based links
9d ago
Jul 29th, 2026
Sublime Security
Attachment: EML with Sharepoint link likely unrelated to sender
9d ago
Jul 29th, 2026
Sublime Security
Attachment: Encrypted PDF with credential theft body
9d ago
Jul 29th, 2026
Sublime Security