Tactic or Technique: Impersonation: Brand

Brand impersonation is a phishing technique where attackers copy the look and feel of trusted companies to make their emails seem legitimate. They recreate logos, colors, templates, and writing styles to mimic well-known brands like Microsoft, Amazon, or PayPal and convince you to trust the message.
They often use lookalike domains to make the links seem real. That could be a small typo, a character swap, or a URL like secure-microsoft[.]com that looks legitimate at first glance. These tricks are meant to get past your defenses and make you more likely to click or respond.
The goal is usually to steal your credentials or convince you to take some kind of action. But over time, these attacks also make it harder to trust what you see in your inbox. Spotting them means looking closely—at the sender address, the way the message is written, and where the links actually go. The differences are subtle, but once you know what to look for, they stand out.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Attachment: Microsoft OAuth credential harvesting via EML with embedded malicious links
12h ago
Jun 1st, 2026
Sublime Security
Brand impersonation: USPS
14h ago
Jun 1st, 2026
Sublime Security
Brand impersonation: Sharepoint
14h ago
Jun 1st, 2026
Sublime Security
Brand impersonation: Adobe Acrobat Sign PDF phishing file format template
14h ago
Jun 1st, 2026
Sublime Security
Brand impersonation: Quickbooks
15h ago
Jun 1st, 2026
Sublime Security
Brand impersonation: DocuSign
20h ago
Jun 1st, 2026
Sublime Security
Brand Impersonation: PayPal
21h ago
Jun 1st, 2026
Sublime Security
Brand impersonation: Adobe with suspicious language and link
22h ago
Jun 1st, 2026
Sublime Security
Brand impersonation: Meta and subsidiaries
4d ago
May 29th, 2026
Sublime Security
Attachment: Compensation-themed DOCX with QR code credential theft
4d ago
May 29th, 2026
Sublime Security
Brand impersonation: Figma with malicious document access overlay
6d ago
May 27th, 2026
Sublime Security
Brand impersonation: DHL
7d ago
May 26th, 2026
Sublime Security
Brand Impersonation: Procore
7d ago
May 26th, 2026
Sublime Security
Brand impersonation: Dashlane
7d ago
May 26th, 2026
Sublime Security
Link: Google Cloud Storage impersonating with googledrive in URL path
7d ago
May 26th, 2026
Sublime Security
Credential phishing: Onedrive impersonation
7d ago
May 26th, 2026
Sublime Security
Brand Impersonation: Social Security Administration (SSA)
12d ago
May 21st, 2026
Sublime Security
Service abuse: Elastic alerts extortion
12d ago
May 21st, 2026
Sublime Security
Service abuse: Calendly callback scam detection
12d ago
May 21st, 2026
Sublime Security
Impersonation: Legal firm with copyright infringement notice
12d ago
May 21st, 2026
Sublime Security