Tactic or Technique: Impersonation: Brand

Brand impersonation is a phishing technique where attackers copy the look and feel of trusted companies to make their emails seem legitimate. They recreate logos, colors, templates, and writing styles to mimic well-known brands like Microsoft, Amazon, or PayPal and convince you to trust the message.
They often use lookalike domains to make the links seem real. That could be a small typo, a character swap, or a URL like secure-microsoft[.]com that looks legitimate at first glance. These tricks are meant to get past your defenses and make you more likely to click or respond.
The goal is usually to steal your credentials or convince you to take some kind of action. But over time, these attacks also make it harder to trust what you see in your inbox. Spotting them means looking closely—at the sender address, the way the message is written, and where the links actually go. The differences are subtle, but once you know what to look for, they stand out.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Service abuse: Google callback scam
4h ago
Oct 6th, 2026
Sublime Security
Brand impersonation: ConstructConnect
5h ago
Oct 6th, 2026
Sublime Security
Link: Malformed subdomain ending in hyphen
5h ago
Oct 6th, 2026
Sublime Security
Service Abuse: American Express callback scam
5h ago
Oct 6th, 2026
Sublime Security
Link: Google Cloud Storage with short-path link delivery
5h ago
Oct 6th, 2026
Sublime Security
Link: Observed URL path (lht) with recipient email address
5h ago
Oct 6th, 2026
Sublime Security
Brand impersonation: Amazon
1d ago
Oct 5th, 2026
Sublime Security
Link: Possible Intuit link abuse
1d ago
Oct 5th, 2026
Sublime Security
Attachment: Microsoft OAuth credential harvesting via EML with embedded malicious links
2d ago
Oct 4th, 2026
Sublime Security
Service abuse: Microsoft Power Apps callback scam
4d ago
Oct 2nd, 2026
Sublime Security
Brand impersonation: Google Authenticator
4d ago
Oct 2nd, 2026
Sublime Security
Brand impersonation: DHL
5d ago
Oct 1st, 2026
Sublime Security
Attachment: PDF including a Microsoft lure with specific signature
5d ago
Oct 1st, 2026
Sublime Security
Credential phishing: Email delivery failure impersonation
5d ago
Oct 1st, 2026
Sublime Security
Brand Impersonation: PayPal
5d ago
Oct 1st, 2026
Sublime Security
Brand impersonation: QuickBooks
6d ago
Sep 30th, 2026
Sublime Security
Brand impersonation: Wix
6d ago
Sep 30th, 2026
Sublime Security
Brand impersonation: Okta
7d ago
Sep 29th, 2026
Sublime Security
Attachment: HTML smuggling with dynamically constructed redirect URL
7d ago
Sep 29th, 2026
Sublime Security
Attachment: Oversized guest-list calendar invite with purchase order lure
8d ago
Sep 28th, 2026
Sublime Security