Tactic or Technique: Free subdomain host

Attackers often use free subdomain hosting platforms—like *.web.app, *.netlify.app, or *.github.io—to create phishing sites that look more trustworthy than they are. These services let anyone spin up a website under a well-known domain, which helps malicious pages inherit the reputation of the larger platform.
When you get a phishing email with a link to one of these subdomains, the parent domain may look familiar and safe. But the subdomain itself often hosts fake login pages or malware downloads, making it hard to tell what’s real and what’s not.
Because these hosting providers are widely used for legitimate purposes, blocking them outright isn’t practical for most organizations. That makes this tactic especially tricky—it hides malicious content behind domains people trust, and it forces defenders to find more precise ways to detect threats without disrupting day-to-day business.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Link: Tycoon2FA phishing kit (non-exhaustive)
12h ago
Jan 23rd, 2026
Sublime Security
/feeds/core/detection-rules/link-tycoon2fa-phishing-kit-non-exhaustive-a070d4e2
Brand impersonation: Fake Fax
2d ago
Jan 21st, 2026
Sublime Security
/feeds/core/detection-rules/brand-impersonation-fake-fax-2a96b90a
Link: Breely link masquerading as PDF
7d ago
Jan 16th, 2026
Sublime Security
/feeds/core/detection-rules/link-breely-link-masquerading-as-pdf-4a498c21
Self-sent fake PDF attachment with misleading link
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/self-sent-fake-pdf-attachment-with-misleading-link-8a285d2e
ClickFunnels link infrastructure abuse
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/clickfunnels-link-infrastructure-abuse-9192fbe9
Attachment: PDF with credential theft language and link to a free subdomain (unsolicited)
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/attachment-pdf-with-credential-theft-language-and-link-to-a-free-subdomain-unsolicited-90f4ef4e
Low reputation link to auto-downloaded HTML file with smuggling indicators
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/low-reputation-link-to-auto-downloaded-html-file-with-smuggling-indicators-339676c6
Attachment: HTML smuggling Microsoft sign in
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/attachment-html-smuggling-microsoft-sign-in-878d6385
Credential phishing: Onedrive impersonation
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/credential-phishing-onedrive-impersonation-1f990c92
Message traversed multiple onmicrosoft.com tenants
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/message-traversed-multiple-onmicrosoftcom-tenants-9cf01c0d
Link: IPFS
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/link-ipfs-19fa6442
Link: Jensi file preview link from unsolicited sender
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/link-jensi-file-preview-link-from-unsolicited-sender-122b39f3
Free subdomain link with login or captcha (untrusted sender)
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/free-subdomain-link-with-login-or-captcha-untrusted-sender-93288f82
Link: Free subdomain host with undisclosed recipients
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/link-free-subdomain-host-with-undisclosed-recipients-c23d979d
Zoom Events newsletter abuse
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/zoom-events-newsletter-abuse-c8fce846
Service abuse: Random Google Firebase sender address with suspicious content
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/service-abuse-random-google-firebase-sender-address-with-suspicious-content-9f8899a9
Deceptive Dropbox mention
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/deceptive-dropbox-mention-58a107bc
Service abuse: Google application integration redirecting to suspicious hosts
1mo ago
Dec 17th, 2025
Sublime Security
/feeds/core/detection-rules/service-abuse-google-application-integration-redirecting-to-suspicious-hosts-473d3247
Link: Cryptocurrency fraud with suspicious links
1mo ago
Dec 1st, 2025
Sublime Security
/feeds/core/detection-rules/link-cryptocurrency-fraud-with-suspicious-links-d0da37ce
Attachment: EML file with IPFS links
2mo ago
Nov 4th, 2025
Sublime Security
/feeds/core/detection-rules/attachment-eml-file-with-ipfs-links-1fe9d7e7