Tactic or Technique: Image as content

Phishing attacks sometimes use images instead of text to hide their intent and evade detection. This technique, often called “image as content,” involves embedding fake login prompts, alerts, or messages inside graphics that look legitimate but can’t be scanned by traditional text-based filters.
These images often appear polished and professional, using logos and layouts that mimic real companies. In many cases, the image itself is clickable and leads you to a phishing site. With little or no surrounding text, the message is more likely to slip through security scans and still look convincing.
This tactic works because visuals feel trustworthy. A branded banner or alert can seem more legitimate than a plain-text email. That’s why defending against it is harder. Traditional filters struggle to analyze image content, so stopping these attacks often requires a combination of advanced image scanning and the ability to recognize visual red flags—not just suspicious text.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Brand impersonation: Fake Fax
2d ago
Jan 21st, 2026
Sublime Security
/feeds/core/detection-rules/brand-impersonation-fake-fax-2a96b90a
Brand impersonation: USPS
3d ago
Jan 20th, 2026
Sublime Security
/feeds/core/detection-rules/brand-impersonation-usps-28b9130a
Credential phishing: Image as content, short or no body contents
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/credential-phishing-image-as-content-short-or-no-body-contents-01313f38
Attachment: Fake secure message and suspicious indicators
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/attachment-fake-secure-message-and-suspicious-indicators-20a34d94
Attachment: QR code link with base64-encoded recipient address
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/attachment-qr-code-link-with-base64-encoded-recipient-address-927a0c1a
Image as content with a link to an open redirect (unsolicited)
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/image-as-content-with-a-link-to-an-open-redirect-unsolicited-f5cec36b
Brand impersonation: Microsoft with low reputation links
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/brand-impersonation-microsoft-with-low-reputation-links-b59201b6
Attachment: QR code with userinfo portion
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/attachment-qr-code-with-userinfo-portion-9d62cc5c
Attachment: Callback phishing solicitation via image file
11d ago
Jan 12th, 2026
@vector_sec
/feeds/core/detection-rules/attachment-callback-phishing-solicitation-via-image-file-60acbb36
Brand impersonation: Microsoft Planner with suspicious link
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/brand-impersonation-microsoft-planner-with-suspicious-link-ea363c08
Attachment: Adobe image lure in body or attachment with suspicious link
18d ago
Jan 5th, 2026
Sublime Security
/feeds/core/detection-rules/attachment-adobe-image-lure-in-body-or-attachment-with-suspicious-link-1d7add81
Credential theft: Gophish abuse with hidden tracking image
2mo ago
Nov 5th, 2025
Sublime Security
/feeds/core/detection-rules/credential-theft-gophish-abuse-with-hidden-tracking-image-59915ceb
Spam: Mastercard promotional content with image-based body
2mo ago
Nov 5th, 2025
Sublime Security
/feeds/core/detection-rules/spam-mastercard-promotional-content-with-image-based-body-5f2cb559
Brand impersonation: DocuSign with embedded QR code
3mo ago
Oct 17th, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-docusign-with-embedded-qr-code-f5cde463
Cloud storage impersonation with credential theft indicators
4mo ago
Sep 22nd, 2025
Sublime Security
/feeds/core/detection-rules/cloud-storage-impersonation-with-credential-theft-indicators-4c20f72c
Attachment: Fake scan-to-email
4mo ago
Sep 22nd, 2025
Sublime Security
/feeds/core/detection-rules/attachment-fake-scan-to-email-ea850cc1
Brand impersonation: Coinbase with suspicious links
4mo ago
Sep 22nd, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-coinbase-with-suspicious-links-b61e2f8e
Attachment: Fake attachment image lure
4mo ago
Sep 22nd, 2025
Sublime Security
/feeds/core/detection-rules/attachment-fake-attachment-image-lure-96b8b285
Attachment: SVG files with evasion elements
5mo ago
Aug 8th, 2025
Sublime Security
/feeds/core/detection-rules/attachment-svg-files-with-evasion-elements-5d2dbb60
Spam: Item giveaway spam template
5mo ago
Aug 5th, 2025
Sublime Security
/feeds/core/detection-rules/spam-item-giveaway-spam-template-06a5f93b