Tactic or Technique: Evasion

Evasion techniques help attackers sneak past email security filters by hiding or disguising malicious content. These tactics are designed to fool both traditional scanners and newer AI-based systems by changing how the message is structured or displayed.
You might see phishing content buried under blocks of harmless-looking text, or important details shown as images so they can't be scanned. Some messages break up keywords using hidden HTML or use misspelled words and lookalike characters to trick you into missing the signs.
More advanced versions use JavaScript that reveals the payload only after the message has passed through security checks. Others try to confuse AI systems with prompt injection or strange formatting.
These techniques create gaps in protection and give attackers a better chance of reaching your inbox. Spotting them early is key. The more familiar you are with how these tricks work, the easier it is to catch them before they do damage.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Link: Microsoft protected message with suspicious recipient patterns
2h ago
Aug 27th, 2026
Sublime Security
Body: HTML whitespace stuffing with short initial message
2h ago
Aug 27th, 2026
Sublime Security
Body: CSS clamp() font obfuscation with suspicious URL
20h ago
Aug 26th, 2026
Sublime Security
ClickFix: Clipboard hijack lure with copy-paste-to-terminal instruction
1d ago
Aug 26th, 2026
Sublime Security
Link: Self-sender with sender org in subject and credential theft indicator
2d ago
Aug 25th, 2026
Sublime Security
Link: Credential harvesting with excess padding evasion
2d ago
Aug 25th, 2026
Sublime Security
Link: Google Cloud Storage link with redirect.html in URL
3d ago
Aug 24th, 2026
Sublime Security
Link: Double base64-encoded URL path
3d ago
Aug 24th, 2026
Sublime Security
Attachment: PDF proposal with credential theft indicators
3d ago
Aug 24th, 2026
Sublime Security
Link: Credential phishing link with undisclosed recipients
3d ago
Aug 24th, 2026
Sublime Security
Attachment: PDF with suspicious HeadlessChrome metadata
3d ago
Aug 24th, 2026
Sublime Security
Attachment: ZIP containing Office binary with embedded DLL
3d ago
Aug 24th, 2026
Sublime Security
Attachment: ICS calendar invite with financial lure and suspicious link
5d ago
Aug 22nd, 2026
Sublime Security
Evasion: Suspicious TLD link redirecting to Wikipedia
6d ago
Aug 21st, 2026
Sublime Security
Link: Credential phishing with obfuscated JavaScript redirect
6d ago
Aug 21st, 2026
Sublime Security
Observed IOC: Mail transiting OFAC-sanctioned bulletproof host Aeza Group
7d ago
Aug 20th, 2026
Sublime Security
Observed IOC: Mail transiting bulletproof host - SmartApe
7d ago
Aug 20th, 2026
Sublime Security
Spamhaus: Mail transiting an ASN-DROP listed network
7d ago
Aug 20th, 2026
Sublime Security
Spamhaus: Mail transiting a DROP listed network
7d ago
Aug 20th, 2026
Sublime Security
Link: RTL text reversal with recipient email in URL
7d ago
Aug 20th, 2026
Sublime Security