Tactic or Technique: Image as content

Phishing attacks sometimes use images instead of text to hide their intent and evade detection. This technique, often called “image as content,” involves embedding fake login prompts, alerts, or messages inside graphics that look legitimate but can’t be scanned by traditional text-based filters.
These images often appear polished and professional, using logos and layouts that mimic real companies. In many cases, the image itself is clickable and leads you to a phishing site. With little or no surrounding text, the message is more likely to slip through security scans and still look convincing.
This tactic works because visuals feel trustworthy. A branded banner or alert can seem more legitimate than a plain-text email. That’s why defending against it is harder. Traditional filters struggle to analyze image content, so stopping these attacks often requires a combination of advanced image scanning and the ability to recognize visual red flags—not just suspicious text.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Brand impersonation: Kroger
1d ago
Sep 15th, 2026
Sublime Security
Impersonation: SAM/SBA federal registration
5d ago
Sep 11th, 2026
Sublime Security
Brand impersonation: USPS
6d ago
Sep 10th, 2026
Sublime Security
Attachment: ICS calendar invite with photo/file share lure
7d ago
Sep 9th, 2026
Sublime Security
Attachment: Gzip-archived with nested HTML file containing image and button link
13d ago
Sep 3rd, 2026
Sublime Security
Brand impersonation: Microsoft with low reputation links
20d ago
Aug 27th, 2026
Sublime Security
Attachment: Risk assessment PDF with inline image
22d ago
Aug 25th, 2026
Sublime Security
Brand impersonation: Microsoft logo image linking to free file host
26d ago
Aug 21st, 2026
Sublime Security
Attachment: Image-only docx/pptx callback phishing
26d ago
Aug 21st, 2026
Sublime Security
Brand impersonation: Greetings Island
29d ago
Aug 18th, 2026
Sublime Security
Brand impersonation: Microsoft Planner with suspicious link
1mo ago
Aug 12th, 2026
Sublime Security
Attachment: PDF with secure document acknowledgment prompt
2mo ago
Jul 17th, 2026
Sublime Security
Attachment: Microsoft SharePoint Impersonation via images in macro-enabled attachment
2mo ago
Jul 16th, 2026
Sublime Security
Attachment: Romance scam with image lure and advance-fee or suspicious link indicators
2mo ago
Jul 1st, 2026
Sublime Security
Cloud storage impersonation with credential theft indicators
2mo ago
Jun 30th, 2026
Sublime Security
Brand impersonation: Fake procurement/RFQ PDF from energy and industrial companies
2mo ago
Jun 25th, 2026
Sublime Security
Brand impersonation: Fake Fax
3mo ago
Jun 17th, 2026
Sublime Security
Spam: BlackBaud infrastructure abuse
3mo ago
Jun 5th, 2026
Sublime Security
Attachment: Adobe image lure in body or attachment with suspicious link
3mo ago
Jun 5th, 2026
Sublime Security
Attachment: Fake attachment image lure
3mo ago
Jun 5th, 2026
Sublime Security