Attack Type: Malware/Ransomware

Malware and Ransomware attacks are designed to infect your system through things like fake invoices, password-protected attachments, or files disguised as routine business documents. Once opened, they quietly install malicious software that can steal data, encrypt files, or open the door for more serious threats.
You might see things like macro-enabled Office documents, HTML attachments, or ZIP files that require a password. These are tricks to get around email filters and convince you to interact. Once the malware runs, it can connect to attacker-controlled servers, spread across your network, and even bring in more payloads.
Ransomware is especially damaging. It locks up your files and demands a payment—usually in cryptocurrency—to get them back. Some attackers also steal data and threaten to leak it if the ransom isn’t paid, a tactic known as double extortion. The impact can be severe, including downtime, lost data, financial loss, and reputational damage.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Observed IOC: Malicious sender domains
4d ago
Jun 19th, 2026
Sublime Security
Observed IOC: Malicious sender email addresses
4d ago
Jun 19th, 2026
Sublime Security
Attachment: PDF Object Hash associated with fake Canada Revenue Agency documents
6d ago
Jun 17th, 2026
Sublime Security
Attachment: Fake PDF Invoices Yara
7d ago
Jun 16th, 2026
Sublime Security
Attachment: MS OOXML file created by Administrator with zero edit time
11d ago
Jun 12th, 2026
Sublime Security
Observed IOC: Malicious sender root domains
11d ago
Jun 12th, 2026
Sublime Security
Service abuse: Suspicious Datadog alert
12d ago
Jun 11th, 2026
Sublime Security
Observed IOC: Malicious domains in body links
13d ago
Jun 10th, 2026
Sublime Security
Attachment: PDF Object Hash with Blue File Icon
18d ago
Jun 5th, 2026
Sublime Security
VIP Impersonation via Google Group relay with suspicious indicators
18d ago
Jun 5th, 2026
Sublime Security
Attachment with auto-executing macro (unsolicited)
18d ago
Jun 5th, 2026
Sublime Security
Attachment: Fake attachment image lure
18d ago
Jun 5th, 2026
Sublime Security
Link: PDF file disguised as HTML page
18d ago
Jun 5th, 2026
Sublime Security
Service abuse: Linode Objects HTML file hosting
18d ago
Jun 5th, 2026
Sublime Security
Attachment: ICS file with excessive custom properties
21d ago
Jun 2nd, 2026
Sublime Security
Link: Numeric IP obfuscation in URL
26d ago
May 28th, 2026
Sublime Security
Observed IOC: Malicious root domains in body links
27d ago
May 27th, 2026
Sublime Security
Image as content with a link to an open redirect
28d ago
May 26th, 2026
Sublime Security
Attachment: SVG file with HTML entity encoded href attributes
1mo ago
May 20th, 2026
Sublime Security
Observed IOC: Malicious URLs in body links
1mo ago
May 19th, 2026
Sublime Security