Tactic or Technique: Image as content

Phishing attacks sometimes use images instead of text to hide their intent and evade detection. This technique, often called “image as content,” involves embedding fake login prompts, alerts, or messages inside graphics that look legitimate but can’t be scanned by traditional text-based filters.
These images often appear polished and professional, using logos and layouts that mimic real companies. In many cases, the image itself is clickable and leads you to a phishing site. With little or no surrounding text, the message is more likely to slip through security scans and still look convincing.
This tactic works because visuals feel trustworthy. A branded banner or alert can seem more legitimate than a plain-text email. That’s why defending against it is harder. Traditional filters struggle to analyze image content, so stopping these attacks often requires a combination of advanced image scanning and the ability to recognize visual red flags—not just suspicious text.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Attachment: Fake email body embedded in inline image
1d ago
Oct 5th, 2026
Sublime Security
Credential phishing: Hyper-linked image leading to free file host
7d ago
Sep 29th, 2026
Sublime Security
Attachment: Image-only docx/pptx callback phishing
8d ago
Sep 28th, 2026
Sublime Security
Attachment: QR code with userinfo portion
8d ago
Sep 28th, 2026
Sublime Security
Attachment: Callback phishing solicitation via image file
8d ago
Sep 28th, 2026
@vector_sec
Brand impersonation: Fake Fax
11d ago
Sep 25th, 2026
Sublime Security
Attachment: PDF with version-only producer and default metadata
11d ago
Sep 25th, 2026
Sublime Security
Attachment: Fake secure message and suspicious indicators
13d ago
Sep 23rd, 2026
Sublime Security
Attachment: Microsoft impersonation via PDF with link and suspicious language
13d ago
Sep 23rd, 2026
Sublime Security
Attachment: Fake attachment image lure
13d ago
Sep 23rd, 2026
Sublime Security
Brand impersonation: DocuSign with embedded QR code
13d ago
Sep 23rd, 2026
Sublime Security
Attachment: Adobe image lure in body or attachment with suspicious link
13d ago
Sep 23rd, 2026
Sublime Security
Image as content with a link to an open redirect
13d ago
Sep 23rd, 2026
Sublime Security
Brand impersonation: Microsoft with low reputation links
13d ago
Sep 23rd, 2026
Sublime Security
Spam: Mastercard promotional content with image-based body
13d ago
Sep 23rd, 2026
Sublime Security
Brand impersonation: USPS
13d ago
Sep 23rd, 2026
Sublime Security
Spam: Item giveaway spam template
13d ago
Sep 23rd, 2026
Sublime Security
Brand impersonation: Microsoft Planner with suspicious link
13d ago
Sep 23rd, 2026
Sublime Security
Cloud storage impersonation with credential theft indicators
13d ago
Sep 23rd, 2026
Sublime Security
Attachment: QR code link with encoded recipient address
14d ago
Sep 22nd, 2026
Sublime Security