Tactic or Technique: Free email provider

Attackers often use free email services like Gmail, Hotmail, and Yahoo to send phishing messages that are harder to detect. These platforms are widely trusted and have high deliverability, which makes it easier for malicious emails to land in your inbox.
It only takes a few minutes for an attacker to create a throwaway account. From there, they can spoof a display name to look like a coworker, vendor, or partner. Since free email addresses are often used in real conversations, the message may not seem out of place.
This tactic works because it blends in. A message might look clean, use a familiar name, and avoid anything that would trigger a filter. If you’re not paying close attention, it’s easy to miss the signs and respond without realizing the sender isn’t who they claim to be.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Credential phishing: Engaging language and other indicators (untrusted sender)
21d ago
Dec 12th, 2025
Sublime Security
/feeds/core/detection-rules/credential-phishing-engaging-language-and-other-indicators-untrusted-sender-c2bc8ca2
Scam: Piano giveaway
22d ago
Dec 11th, 2025
Sublime Security
/feeds/core/detection-rules/scam-piano-giveaway-1a91a203
Suspicious request for financial information
27d ago
Dec 6th, 2025
Sublime Security
/feeds/core/detection-rules/suspicious-request-for-financial-information-4ebdaa4d
Spam: Fake dating profile notification
1mo ago
Dec 3rd, 2025
Sublime Security
/feeds/core/detection-rules/spam-fake-dating-profile-notification-0f33fea2
Spam: SMTP & Proxy Communications in Email Body
1mo ago
Dec 2nd, 2025
Sublime Security
/feeds/core/detection-rules/spam-smtp-and-proxy-communications-in-email-body-2bdc6a3b
Reconnaissance: Short generic greeting message
1mo ago
Dec 2nd, 2025
Sublime Security
/feeds/core/detection-rules/reconnaissance-short-generic-greeting-message-c67dedab
Link abuse: Self-service creation platform link with suspicious recipient behavior
1mo ago
Dec 2nd, 2025
Sublime Security
/feeds/core/detection-rules/link-abuse-self-service-creation-platform-link-with-suspicious-recipient-behavior-384ad135
BEC/Fraud: Job scam fake thread or plaintext pivot to freemail
1mo ago
Nov 20th, 2025
Sublime Security
/feeds/core/detection-rules/becfraud-job-scam-fake-thread-or-plaintext-pivot-to-freemail-ce21c151
Service abuse: Google Drive share from new reply-to domain
1mo ago
Nov 13th, 2025
Sublime Security
/feeds/core/detection-rules/service-abuse-google-drive-share-from-new-reply-to-domain-c1a2d367
VIP Impersonation via Google Group relay with suspicious indicators
1mo ago
Nov 12th, 2025
Sublime Security
/feeds/core/detection-rules/vip-impersonation-via-google-group-relay-with-suspicious-indicators-57f9cd3b
Spam: Sexually explicit Google group invitation
1mo ago
Nov 12th, 2025
Sublime Security
/feeds/core/detection-rules/spam-sexually-explicit-google-group-invitation-4e0bec29
ClickFunnels link infrastructure abuse
1mo ago
Nov 4th, 2025
Sublime Security
/feeds/core/detection-rules/clickfunnels-link-infrastructure-abuse-9192fbe9
Link: Apple App Store malicious ad manager themed apps from free email provider
2mo ago
Oct 17th, 2025
Sublime Security
/feeds/core/detection-rules/link-apple-app-store-malicious-ad-manager-themed-apps-from-free-email-provider-9ce402c6
Link: Apple TestFlight from free email provider
2mo ago
Oct 17th, 2025
Sublime Security
/feeds/core/detection-rules/link-apple-testflight-from-free-email-provider-9b447f1f
Constant Contact link infrastructure abuse
2mo ago
Oct 17th, 2025
Sublime Security
/feeds/core/detection-rules/constant-contact-link-infrastructure-abuse-8c5e8e4c
Callback phishing solicitation in message body
2mo ago
Oct 17th, 2025
Sublime Security
/feeds/core/detection-rules/callback-phishing-solicitation-in-message-body-10a3a446
Callback phishing via e-signature service
2mo ago
Oct 17th, 2025
Sublime Security
/feeds/core/detection-rules/callback-phishing-via-e-signature-service-ed37b4fd
Spam: Sexually explicit Looker Studio report
3mo ago
Oct 2nd, 2025
Sublime Security
/feeds/core/detection-rules/spam-sexually-explicit-looker-studio-report-f1e649cd
Attachment: Callback phishing solicitation via image file
3mo ago
Sep 25th, 2025
@vector_sec
/feeds/core/detection-rules/attachment-callback-phishing-solicitation-via-image-file-60acbb36
Link: PDF and financial display text to free file host
3mo ago
Sep 24th, 2025
Sublime Security
/feeds/core/detection-rules/link-pdf-and-financial-display-text-to-free-file-host-b010740b