Tactic or Technique: Impersonation: Brand

Brand impersonation is a phishing technique where attackers copy the look and feel of trusted companies to make their emails seem legitimate. They recreate logos, colors, templates, and writing styles to mimic well-known brands like Microsoft, Amazon, or PayPal and convince you to trust the message.
They often use lookalike domains to make the links seem real. That could be a small typo, a character swap, or a URL like secure-microsoft[.]com that looks legitimate at first glance. These tricks are meant to get past your defenses and make you more likely to click or respond.
The goal is usually to steal your credentials or convince you to take some kind of action. But over time, these attacks also make it harder to trust what you see in your inbox. Spotting them means looking closely—at the sender address, the way the message is written, and where the links actually go. The differences are subtle, but once you know what to look for, they stand out.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Attachment: PDF with Microsoft Purview message impersonation
2d ago
Nov 10th, 2025
Sublime Security
/feeds/core/detection-rules/attachment-pdf-with-microsoft-purview-message-impersonation-571d4964
Brand impersonation: Survey request with credential theft indicators
4d ago
Nov 8th, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-survey-request-with-credential-theft-indicators-ea1c0e09
Brand impersonation: Microsoft with low reputation links
4d ago
Nov 8th, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-microsoft-with-low-reputation-links-b59201b6
Brand impersonation: SharePoint PDF attachment with credential theft language
5d ago
Nov 7th, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-sharepoint-pdf-attachment-with-credential-theft-language-ae3756fa
Brand impersonation: SendGrid
5d ago
Nov 7th, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-sendgrid-d800124f
Brand impersonation: Paperless Post
6d ago
Nov 6th, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-paperless-post-e9ec5e09
Brand impersonation: USPS
7d ago
Nov 5th, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-usps-28b9130a
Spam: Mastercard promotional content with image-based body
7d ago
Nov 5th, 2025
Sublime Security
/feeds/core/detection-rules/spam-mastercard-promotional-content-with-image-based-body-5f2cb559
Brand impersonation: Amazon
8d ago
Nov 4th, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-amazon-13fc967d
Brand impersonation: Coinbase
8d ago
Nov 4th, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-coinbase-3dca757a
Callback phishing via extensionless rfc822 attachment
8d ago
Nov 4th, 2025
Sublime Security
/feeds/core/detection-rules/callback-phishing-via-extensionless-rfc822-attachment-197722c4
Brand impersonation: Twitter
9d ago
Nov 3rd, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-twitter-013c32c2
Brand impersonation: Booking.com
9d ago
Nov 3rd, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-bookingcom-d1d8882f
Spam/fraud: Predatory journal/research paper request
9d ago
Nov 3rd, 2025
Sublime Security
/feeds/core/detection-rules/spamfraud-predatory-journalresearch-paper-request-263ca56b
Brand impersonation: Github
9d ago
Nov 3rd, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-github-9402f92b
Link: File sharing impersonation with suspicious language and sending patterns
12d ago
Oct 31st, 2025
Sublime Security
/feeds/core/detection-rules/link-file-sharing-impersonation-with-suspicious-language-and-sending-patterns-d3363041
Brand impersonation: TikTok
13d ago
Oct 30th, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-tiktok-aaacc8b7
Brand impersonation: Meta and subsidiaries
13d ago
Oct 30th, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-meta-and-subsidiaries-e38f1e3b
Brand Impersonation: ShareFile
14d ago
Oct 29th, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-sharefile-f8330307
Brand impersonation: Discord notification
20d ago
Oct 23rd, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-discord-notification-97007826