Tactic or Technique: Free subdomain host

Attackers often use free subdomain hosting platforms—like *.web.app, *.netlify.app, or *.github.io—to create phishing sites that look more trustworthy than they are. These services let anyone spin up a website under a well-known domain, which helps malicious pages inherit the reputation of the larger platform.
When you get a phishing email with a link to one of these subdomains, the parent domain may look familiar and safe. But the subdomain itself often hosts fake login pages or malware downloads, making it hard to tell what’s real and what’s not.
Because these hosting providers are widely used for legitimate purposes, blocking them outright isn’t practical for most organizations. That makes this tactic especially tricky—it hides malicious content behind domains people trust, and it forces defenders to find more precise ways to detect threats without disrupting day-to-day business.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Attachment: ICS calendar invite with bid/RFP lure and suspicious link
22h ago
Sep 15th, 2026
Sublime Security
Attachment: Excel file with hyperlinks to suspicious domains
5d ago
Sep 11th, 2026
Sublime Security
Self-sent fake PDF attachment with misleading link
7d ago
Sep 9th, 2026
Sublime Security
Attachment: ICS file with credential theft indicators
12d ago
Sep 4th, 2026
Sublime Security
Attachment: RTF with link to free-hosted Cloudflare Pages
1mo ago
Aug 13th, 2026
Sublime Security
Link: URL shortener chaining to workers.dev redirect
1mo ago
Aug 10th, 2026
Sublime Security
Low reputation link to auto-downloaded HTML file with smuggling indicators
1mo ago
Jul 29th, 2026
Sublime Security
Attachment: EML with link to credential phishing page
1mo ago
Jul 27th, 2026
Sublime Security
Credential phishing: Onedrive impersonation
2mo ago
Jul 16th, 2026
Sublime Security
Link: Fraudulent state business filing notice
2mo ago
Jul 14th, 2026
Sublime Security
Brand impersonation: Government / Tax Authority document lure
2mo ago
Jul 14th, 2026
Sublime Security
Zoom Events newsletter abuse
2mo ago
Jul 8th, 2026
Sublime Security
Service abuse: Google Firebase sender address with suspicious content
3mo ago
Jun 18th, 2026
Sublime Security
Service abuse: Outlook Groups with Google Sites link and evasion tag
3mo ago
Jun 17th, 2026
Sublime Security
Brand impersonation: Fake Fax
3mo ago
Jun 17th, 2026
Sublime Security
Link: Flare-branded credential harvesting via Cloudflare tunnels
3mo ago
Jun 12th, 2026
Sublime Security
Service abuse: Suspicious Datadog alert
3mo ago
Jun 11th, 2026
Sublime Security
ClickFunnels link infrastructure abuse
3mo ago
Jun 5th, 2026
Sublime Security
Attachment: PDF Attachment with links to workers.dev
3mo ago
Jun 4th, 2026
Sublime Security
Credential phishing: AWS Lambda URL with recipient targeting
3mo ago
May 28th, 2026
Sublime Security