Tactic or Technique: Free subdomain host

Attackers often use free subdomain hosting platforms—like *.web.app, *.netlify.app, or *.github.io—to create phishing sites that look more trustworthy than they are. These services let anyone spin up a website under a well-known domain, which helps malicious pages inherit the reputation of the larger platform.
When you get a phishing email with a link to one of these subdomains, the parent domain may look familiar and safe. But the subdomain itself often hosts fake login pages or malware downloads, making it hard to tell what’s real and what’s not.
Because these hosting providers are widely used for legitimate purposes, blocking them outright isn’t practical for most organizations. That makes this tactic especially tricky—it hides malicious content behind domains people trust, and it forces defenders to find more precise ways to detect threats without disrupting day-to-day business.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Service abuse: Lovable-hosted redirect to external phishing page
6h ago
Oct 6th, 2026
Sublime Security
Attachment: Excel file with hyperlinks to suspicious domains
6h ago
Oct 6th, 2026
Sublime Security
Link: Copy-paste browser instruction with suspicious domain
7d ago
Sep 29th, 2026
Sublime Security
ClickFunnels link infrastructure abuse
7d ago
Sep 29th, 2026
Sublime Security
Attachment: ICS calendar with suspicious link Leading to minimal JS landing page
8d ago
Sep 28th, 2026
Sublime Security
Attachment: ICS file with credential theft indicators
8d ago
Sep 28th, 2026
Sublime Security
Attachment: ICS calendar invite with bid/RFP lure and suspicious link
8d ago
Sep 28th, 2026
Sublime Security
Attachment: Calendar invite with suspicious link leading to an open redirect
8d ago
Sep 28th, 2026
Sublime Security
Brand impersonation: Fake Fax
11d ago
Sep 25th, 2026
Sublime Security
Link: Webflow link from unsolicited sender
13d ago
Sep 23rd, 2026
Sublime Security
Link: Jensi file preview link from unsolicited sender
13d ago
Sep 23rd, 2026
Sublime Security
Free subdomain link with login or captcha (untrusted sender)
13d ago
Sep 23rd, 2026
Sublime Security
Self-sent fake PDF attachment with misleading link
27d ago
Sep 9th, 2026
Sublime Security
Attachment: RTF with link to free-hosted Cloudflare Pages
1mo ago
Aug 13th, 2026
Sublime Security
Link: URL shortener chaining to workers.dev redirect
1mo ago
Aug 10th, 2026
Sublime Security
Low reputation link to auto-downloaded HTML file with smuggling indicators
2mo ago
Jul 29th, 2026
Sublime Security
Attachment: EML with link to credential phishing page
2mo ago
Jul 27th, 2026
Sublime Security
Credential phishing: Onedrive impersonation
2mo ago
Jul 16th, 2026
Sublime Security
Link: Fraudulent state business filing notice
2mo ago
Jul 14th, 2026
Sublime Security
Brand impersonation: Government / Tax Authority document lure
2mo ago
Jul 14th, 2026
Sublime Security