Attack Type: Malware/Ransomware

Malware and Ransomware attacks are designed to infect your system through things like fake invoices, password-protected attachments, or files disguised as routine business documents. Once opened, they quietly install malicious software that can steal data, encrypt files, or open the door for more serious threats.
You might see things like macro-enabled Office documents, HTML attachments, or ZIP files that require a password. These are tricks to get around email filters and convince you to interact. Once the malware runs, it can connect to attacker-controlled servers, spread across your network, and even bring in more payloads.
Ransomware is especially damaging. It locks up your files and demands a payment—usually in cryptocurrency—to get them back. Some attackers also steal data and threaten to leak it if the ransom isn’t paid, a tactic known as double extortion. The impact can be severe, including downtime, lost data, financial loss, and reputational damage.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
ClickFix: Clipboard hijack lure with copy-paste-to-terminal instruction
1d ago
Aug 26th, 2026
Sublime Security
Attachment: Risk assessment PDF with inline image
2d ago
Aug 25th, 2026
Sublime Security
Attachment: PDF with suspicious HeadlessChrome metadata
3d ago
Aug 24th, 2026
Sublime Security
Attachment: ZIP containing Office binary with embedded DLL
3d ago
Aug 24th, 2026
Sublime Security
Brand impersonation: Microsoft logo image linking to free file host
6d ago
Aug 21st, 2026
Sublime Security
Observed IOC: Malicious sender email addresses
7d ago
Aug 20th, 2026
Sublime Security
Spamhaus: Mail transiting a DROP listed network
7d ago
Aug 20th, 2026
Sublime Security
Spamhaus: Mail transiting an ASN-DROP listed network
7d ago
Aug 20th, 2026
Sublime Security
Observed IOC: Malicious sender domains
7d ago
Aug 20th, 2026
Sublime Security
Observed IOC: Mail transiting bulletproof host - SmartApe
7d ago
Aug 20th, 2026
Sublime Security
Observed IOC: Mail transiting OFAC-sanctioned bulletproof host Aeza Group
7d ago
Aug 20th, 2026
Sublime Security
Attachment: QuickBooks PDF lure
7d ago
Aug 20th, 2026
Sublime Security
Attachment: PDF with embedded box-lure and javascript
8d ago
Aug 19th, 2026
Sublime Security
Attachment: PDF templated investment lure
8d ago
Aug 19th, 2026
Sublime Security
Brand impersonation: Greetings Island
9d ago
Aug 18th, 2026
Sublime Security
Link: Document-themed link to newly registered domain
9d ago
Aug 18th, 2026
Sublime Security
Service abuse: Soundestlink redirect with suspicious indicators
16d ago
Aug 11th, 2026
Sublime Security
Attachment: PDF with base64 JavaScript and eval functions
16d ago
Aug 11th, 2026
Sublime Security
New link domain (<=10d) from untrusted sender
17d ago
Aug 10th, 2026
Sublime Security
Link: Numeric IP obfuscation in URL
21d ago
Aug 6th, 2026
Sublime Security