Tactic or Technique: Evasion

Evasion techniques help attackers sneak past email security filters by hiding or disguising malicious content. These tactics are designed to fool both traditional scanners and newer AI-based systems by changing how the message is structured or displayed.
You might see phishing content buried under blocks of harmless-looking text, or important details shown as images so they can't be scanned. Some messages break up keywords using hidden HTML or use misspelled words and lookalike characters to trick you into missing the signs.
More advanced versions use JavaScript that reveals the payload only after the message has passed through security checks. Others try to confuse AI systems with prompt injection or strange formatting.
These techniques create gaps in protection and give attackers a better chance of reaching your inbox. Spotting them early is key. The more familiar you are with how these tricks work, the easier it is to catch them before they do damage.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Benefits enrollment impersonation
22h ago
May 11th, 2026
Sublime Security
Attachment: SVG files with evasion elements
4d ago
May 8th, 2026
Sublime Security
Attachment: Suspicious PDF created with headless browser
5d ago
May 7th, 2026
Sublime Security
Observed IOC: Malicious domains in body links
5d ago
May 7th, 2026
Sublime Security
Service abuse: Dropbox Paper with copy-paste instructions
5d ago
May 7th, 2026
Sublime Security
Callback phishing via calendar invite
6d ago
May 6th, 2026
Sublime Security
Service abuse: Zoom with newly registered reply-to domain
8d ago
May 4th, 2026
Sublime Security
Service abuse: Payoneer callback scam
8d ago
May 4th, 2026
Sublime Security
Callback phishing via Zelle Service Abuse
8d ago
May 4th, 2026
Sublime Security
Brand impersonation: SharePoint PDF attachment with credential theft language
8d ago
May 4th, 2026
Sublime Security
Venmo payment request abuse
8d ago
May 4th, 2026
Sublime Security
Brand impersonation: DocuSign with embedded QR code
8d ago
May 4th, 2026
Sublime Security
Link: Credential harvesting with excess padding evasion
8d ago
May 4th, 2026
Sublime Security
PayPal invoice abuse
8d ago
May 4th, 2026
Sublime Security
Callback phishing via Intuit service abuse
8d ago
May 4th, 2026
Sublime Security
Impersonation: Suspected supplier impersonation with suspicious content
8d ago
May 4th, 2026
Sublime Security
Callback phishing via Adobe Sign comment
8d ago
May 4th, 2026
Sublime Security
Callback phishing: SumUp infrastructure abuse
8d ago
May 4th, 2026
Sublime Security
Suspected cross-site scripting (XSS) found in subject
8d ago
May 4th, 2026
Sublime Security
Link: BEC with newly registered domains and financial keywords
11d ago
May 1st, 2026
Sublime Security