Tactic or Technique: Evasion

Evasion techniques help attackers sneak past email security filters by hiding or disguising malicious content. These tactics are designed to fool both traditional scanners and newer AI-based systems by changing how the message is structured or displayed.
You might see phishing content buried under blocks of harmless-looking text, or important details shown as images so they can't be scanned. Some messages break up keywords using hidden HTML or use misspelled words and lookalike characters to trick you into missing the signs.
More advanced versions use JavaScript that reveals the payload only after the message has passed through security checks. Others try to confuse AI systems with prompt injection or strange formatting.
These techniques create gaps in protection and give attackers a better chance of reaching your inbox. Spotting them early is key. The more familiar you are with how these tricks work, the easier it is to catch them before they do damage.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Attachment: ICS voicemail lure with suspicious link
1h ago
Sep 16th, 2026
Sublime Security
Attachment: PDF with a suspicious string and single URL
2h ago
Sep 16th, 2026
Sublime Security
Suspicious attachment with unscannable Cloudflare link
4h ago
Sep 16th, 2026
Sublime Security
Spamhaus: Mail transiting an ASN-DROP listed network
1d ago
Sep 15th, 2026
Sublime Security
Attachment: Legal themed message or PDF with suspicious indicators
1d ago
Sep 15th, 2026
Sublime Security
Link: Abused Trac-link URL
2d ago
Sep 14th, 2026
Sublime Security
Credential phishing: Generic document sharing
2d ago
Sep 14th, 2026
Sublime Security
Spamhaus: Mail transiting a DROP listed network
2d ago
Sep 14th, 2026
Sublime Security
Spam: Fake photo share
5d ago
Sep 11th, 2026
Sublime Security
Service abuse: Self-service platform redirecting to newly registered suspicious domain
6d ago
Sep 10th, 2026
Sublime Security
Attachment: PDF with EOF MD5 hash marker
6d ago
Sep 10th, 2026
Sublime Security
Attachment: PDF with dub.sh shortened link
7d ago
Sep 9th, 2026
Sublime Security
Self-sent fake PDF attachment with misleading link
7d ago
Sep 9th, 2026
Sublime Security
Body: CVE-2026-42897 Exchange OWA stored XSS
7d ago
Sep 9th, 2026
Sublime Security
Attachment: PDF with bolded passcode
8d ago
Sep 8th, 2026
Sublime Security
Observed IOC: Mail transiting OFAC-sanctioned bulletproof host Aeza Group
8d ago
Sep 8th, 2026
Sublime Security
Brand Impersonation: ShareFile
8d ago
Sep 8th, 2026
Sublime Security
Link: Numeric IP obfuscation in URL
8d ago
Sep 8th, 2026
Sublime Security
Attachment: ICS file with excessive custom properties
12d ago
Sep 4th, 2026
Sublime Security
Attachment: ICS Link With Valueless Base64 Query Parameter
12d ago
Sep 4th, 2026
Sublime Security