Tactic or Technique: Evasion

Evasion techniques help attackers sneak past email security filters by hiding or disguising malicious content. These tactics are designed to fool both traditional scanners and newer AI-based systems by changing how the message is structured or displayed.
You might see phishing content buried under blocks of harmless-looking text, or important details shown as images so they can't be scanned. Some messages break up keywords using hidden HTML or use misspelled words and lookalike characters to trick you into missing the signs.
More advanced versions use JavaScript that reveals the payload only after the message has passed through security checks. Others try to confuse AI systems with prompt injection or strange formatting.
These techniques create gaps in protection and give attackers a better chance of reaching your inbox. Spotting them early is key. The more familiar you are with how these tricks work, the easier it is to catch them before they do damage.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Attachment: Microsoft OAuth credential harvesting via EML with embedded malicious links
12h ago
Jun 1st, 2026
Sublime Security
Body: HTML whitespace stuffing with short initial message
4d ago
May 29th, 2026
Sublime Security
Attachment: ICS calendar file with suspicious product identifier
4d ago
May 29th, 2026
Sublime Security
Link: Numeric IP obfuscation in URL
5d ago
May 28th, 2026
Sublime Security
Service Abuse: HelloSign share with suspicious sender or document name
5d ago
May 28th, 2026
Sublime Security
Link: Self-sender credential theft with configuration placeholder
6d ago
May 27th, 2026
Sublime Security
Service abuse: Google OAuth with suspicious redirect destination
6d ago
May 27th, 2026
Sublime Security
Observed IOC: Malicious root domains in body links
6d ago
May 27th, 2026
Sublime Security
Image as content with a link to an open redirect
7d ago
May 26th, 2026
Sublime Security
Link: Google Cloud Storage with suspicious URL pattern
7d ago
May 26th, 2026
Sublime Security
Credential phishing: Generic document sharing
11d ago
May 22nd, 2026
Sublime Security
Attachment: SVG file with hyperlinks and cursor styling
13d ago
May 20th, 2026
Sublime Security
Attachment: SVG file with HTML entity encoded href attributes
13d ago
May 20th, 2026
Sublime Security
Observed IOC: Malicious domains in body links
14d ago
May 19th, 2026
Sublime Security
Observed IOC: Malicious URLs in body links
14d ago
May 19th, 2026
Sublime Security
Fake thread with suspicious indicators
14d ago
May 19th, 2026
Sublime Security
Attachment: PDF with suspicious link and action-oriented language
15d ago
May 18th, 2026
Sublime Security
Attachment: Small text file with link containing recipient email address
19d ago
May 14th, 2026
Sublime Security
Attachment: Embedded VBScript in MHT file
19d ago
May 14th, 2026
Sublime Security
Attachment: PDF with a suspicious string and single URL
20d ago
May 13th, 2026
Sublime Security