Tactic or Technique: Free subdomain host

Attackers often use free subdomain hosting platforms—like *.web.app, *.netlify.app, or *.github.io—to create phishing sites that look more trustworthy than they are. These services let anyone spin up a website under a well-known domain, which helps malicious pages inherit the reputation of the larger platform.
When you get a phishing email with a link to one of these subdomains, the parent domain may look familiar and safe. But the subdomain itself often hosts fake login pages or malware downloads, making it hard to tell what’s real and what’s not.
Because these hosting providers are widely used for legitimate purposes, blocking them outright isn’t practical for most organizations. That makes this tactic especially tricky—it hides malicious content behind domains people trust, and it forces defenders to find more precise ways to detect threats without disrupting day-to-day business.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Link: Multistage landing - ClickUp abuse
6d ago
Feb 27th, 2026
Sublime Security
/feeds/core/detection-rules/link-multistage-landing-clickup-abuse-78a5d035
Attachment: PDF with multistage landing - ClickUp abuse
6d ago
Feb 27th, 2026
Sublime Security
/feeds/core/detection-rules/attachment-pdf-with-multistage-landing-clickup-abuse-0dc40316
Link: Free file hosting with undisclosed recipients
10d ago
Feb 23rd, 2026
Sublime Security
/feeds/core/detection-rules/link-free-file-hosting-with-undisclosed-recipients-b6281306
Link: WordPress login page with Blogspot Binance scam
16d ago
Feb 17th, 2026
Sublime Security
/feeds/core/detection-rules/link-wordpress-login-page-with-blogspot-binance-scam-909dfae5
Brand impersonation: Fake Fax
28d ago
Feb 5th, 2026
Sublime Security
/feeds/core/detection-rules/brand-impersonation-fake-fax-2a96b90a
ClickFunnels link infrastructure abuse
28d ago
Feb 5th, 2026
Sublime Security
/feeds/core/detection-rules/clickfunnels-link-infrastructure-abuse-9192fbe9
Link: Tycoon2FA phishing kit (non-exhaustive)
1mo ago
Jan 23rd, 2026
Sublime Security
/feeds/core/detection-rules/link-tycoon2fa-phishing-kit-non-exhaustive-a070d4e2
Link: Breely link masquerading as PDF
1mo ago
Jan 16th, 2026
Sublime Security
/feeds/core/detection-rules/link-breely-link-masquerading-as-pdf-4a498c21
Link: IPFS
1mo ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/link-ipfs-19fa6442
Link: Jensi file preview link from unsolicited sender
1mo ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/link-jensi-file-preview-link-from-unsolicited-sender-122b39f3
Free subdomain link with login or captcha (untrusted sender)
1mo ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/free-subdomain-link-with-login-or-captcha-untrusted-sender-93288f82
Link: Free subdomain host with undisclosed recipients
1mo ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/link-free-subdomain-host-with-undisclosed-recipients-c23d979d
Zoom Events newsletter abuse
1mo ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/zoom-events-newsletter-abuse-c8fce846
Service abuse: Random Google Firebase sender address with suspicious content
1mo ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/service-abuse-random-google-firebase-sender-address-with-suspicious-content-9f8899a9
Deceptive Dropbox mention
1mo ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/deceptive-dropbox-mention-58a107bc
Self-sent fake PDF attachment with misleading link
1mo ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/self-sent-fake-pdf-attachment-with-misleading-link-8a285d2e
Attachment: PDF with credential theft language and link to a free subdomain (unsolicited)
1mo ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/attachment-pdf-with-credential-theft-language-and-link-to-a-free-subdomain-unsolicited-90f4ef4e
Low reputation link to auto-downloaded HTML file with smuggling indicators
1mo ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/low-reputation-link-to-auto-downloaded-html-file-with-smuggling-indicators-339676c6
Attachment: HTML smuggling Microsoft sign in
1mo ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/attachment-html-smuggling-microsoft-sign-in-878d6385
Credential phishing: Onedrive impersonation
1mo ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/credential-phishing-onedrive-impersonation-1f990c92