Tactic or Technique: Evasion

Evasion techniques help attackers sneak past email security filters by hiding or disguising malicious content. These tactics are designed to fool both traditional scanners and newer AI-based systems by changing how the message is structured or displayed.
You might see phishing content buried under blocks of harmless-looking text, or important details shown as images so they can't be scanned. Some messages break up keywords using hidden HTML or use misspelled words and lookalike characters to trick you into missing the signs.
More advanced versions use JavaScript that reveals the payload only after the message has passed through security checks. Others try to confuse AI systems with prompt injection or strange formatting.
These techniques create gaps in protection and give attackers a better chance of reaching your inbox. Spotting them early is key. The more familiar you are with how these tricks work, the easier it is to catch them before they do damage.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Headers: Self-sender using Microsoft CompAuth bypass with credential theft content
12h ago
Apr 21st, 2026
Sublime Security
Attachment: ICS calendar file with QR code containing recipient email address
2d ago
Apr 20th, 2026
Sublime Security
Link: WordPress admin targeting with recipient identifier in URL fragment
6d ago
Apr 16th, 2026
Sublime Security
Self-sender with copy/paste instructions and suspicious domains (French/Français)
6d ago
Apr 16th, 2026
Sublime Security
Service abuse: Meetup.com redirect with brand impersonation
7d ago
Apr 15th, 2026
Sublime Security
Attachment: PDF with split QR code
7d ago
Apr 15th, 2026
Sublime Security
Attachment: PDF with a suspicious string and single URL
12d ago
Apr 10th, 2026
Sublime Security
Link: Shortened URL with fragment matching subject
13d ago
Apr 9th, 2026
Sublime Security
Attachment: Encrypted PDF with credential theft body
13d ago
Apr 9th, 2026
Sublime Security
Credential Phishing: W-2 lure with inline SVG Windows logo
14d ago
Apr 8th, 2026
Sublime Security
Service abuse: Mimecast URL with excessive path length
14d ago
Apr 8th, 2026
Sublime Security
Link: Landing page with search-ms protocol redirect
15d ago
Apr 7th, 2026
Sublime Security
Abuse: Cloudflare Workers Hosted EvilTokens Domain Structure
16d ago
Apr 6th, 2026
Sublime Security
Attachment: Encrypted ZIP containing VHDX file
19d ago
Apr 3rd, 2026
Sublime Security
VIP impersonation: Fake thread with display name match, email mismatch
19d ago
Apr 3rd, 2026
Sublime Security
Attachment: Legal themed message or PDF with suspicious indicators
19d ago
Apr 3rd, 2026
Sublime Security
Benefits enrollment impersonation
19d ago
Apr 3rd, 2026
Sublime Security
Attachment: ICS file with AWS Lambda URL
21d ago
Apr 1st, 2026
Sublime Security
Link: Apple TestFlight from suspicious sender
21d ago
Apr 1st, 2026
Sublime Security
Attachment: EML with QR code redirecting to Cloudflare challenges
21d ago
Apr 1st, 2026
Sublime Security