Attack Type: Malware/Ransomware

Malware and Ransomware attacks are designed to infect your system through things like fake invoices, password-protected attachments, or files disguised as routine business documents. Once opened, they quietly install malicious software that can steal data, encrypt files, or open the door for more serious threats.
You might see things like macro-enabled Office documents, HTML attachments, or ZIP files that require a password. These are tricks to get around email filters and convince you to interact. Once the malware runs, it can connect to attacker-controlled servers, spread across your network, and even bring in more payloads.
Ransomware is especially damaging. It locks up your files and demands a payment—usually in cryptocurrency—to get them back. Some attackers also steal data and threaten to leak it if the ransom isn’t paid, a tactic known as double extortion. The impact can be severe, including downtime, lost data, financial loss, and reputational damage.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Link: Numeric IP obfuscation in URL
13h ago
Aug 6th, 2026
Sublime Security
Observed IOC: Malicious sender email addresses
13h ago
Aug 6th, 2026
Sublime Security
Observed IOC: Mail transiting OFAC-sanctioned bulletproof host Aeza Group
2d ago
Aug 5th, 2026
Sublime Security
Observed IOC: Mail transiting bulletproof host - SmartApe
2d ago
Aug 5th, 2026
Sublime Security
AnonymousFox indicators
2d ago
Aug 5th, 2026
Sublime Security
VIP Impersonation via Google Group relay with suspicious indicators
2d ago
Aug 5th, 2026
Sublime Security
Observed IOC: Malicious sender domains
13d ago
Jul 25th, 2026
Sublime Security
Link: ScreenConnect remote access tool delivery with unattended guest access
17d ago
Jul 21st, 2026
Sublime Security
Attachment: ICS file with AWS Lambda URL
22d ago
Jul 16th, 2026
Sublime Security
Attachment: PDF with suspicious document view lure
24d ago
Jul 14th, 2026
Sublime Security
Malformed URL prefix
24d ago
Jul 14th, 2026
Sublime Security
Open redirect: JustPaste.it
1mo ago
Jul 2nd, 2026
Sublime Security
Attachment: PDF with quote lure
1mo ago
Jul 1st, 2026
Sublime Security
Link: Google Cloud Storage redirect to external domain
1mo ago
Jun 30th, 2026
Sublime Security
Attachment: PDF with localhost IP in EXIF title metadata
1mo ago
Jun 29th, 2026
Sublime Security
Brand impersonation: Google Drive fake file share
1mo ago
Jun 26th, 2026
Sublime Security
Attachment: Malicious zip file matching zipline campaign
1mo ago
Jun 25th, 2026
Sublime Security
Attachment: PDF Object Hash associated with fake Canada Revenue Agency documents
1mo ago
Jun 17th, 2026
Sublime Security
Attachment: Fake PDF Invoices Yara
1mo ago
Jun 16th, 2026
Sublime Security
Attachment: MS OOXML file created by Administrator with zero edit time
1mo ago
Jun 12th, 2026
Sublime Security