Attack Type: Malware/Ransomware

Malware and Ransomware attacks are designed to infect your system through things like fake invoices, password-protected attachments, or files disguised as routine business documents. Once opened, they quietly install malicious software that can steal data, encrypt files, or open the door for more serious threats.
You might see things like macro-enabled Office documents, HTML attachments, or ZIP files that require a password. These are tricks to get around email filters and convince you to interact. Once the malware runs, it can connect to attacker-controlled servers, spread across your network, and even bring in more payloads.
Ransomware is especially damaging. It locks up your files and demands a payment—usually in cryptocurrency—to get them back. Some attackers also steal data and threaten to leak it if the ransom isn’t paid, a tactic known as double extortion. The impact can be severe, including downtime, lost data, financial loss, and reputational damage.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Link: Tax document lure Portuguese/Spanish with suspicious domains
6d ago
Apr 14th, 2026
Sublime Security
Service abuse: Mimecast URL with excessive path length
12d ago
Apr 8th, 2026
Sublime Security
Service abuse: GitHub notification with excessive mentions and suspicious links
13d ago
Apr 7th, 2026
Sublime Security
Link: Landing page with search-ms protocol redirect
13d ago
Apr 7th, 2026
Sublime Security
Attachment: Encrypted ZIP containing VHDX file
17d ago
Apr 3rd, 2026
Sublime Security
Link: Personalized URL with recipient address on commonly abused web service
19d ago
Apr 1st, 2026
Sublime Security
Attachment: ICS file with AWS Lambda URL
19d ago
Apr 1st, 2026
Sublime Security
Attachment: EML with QR code redirecting to Cloudflare challenges
19d ago
Apr 1st, 2026
Sublime Security
Brand impersonation: Zoom with deceptive link display
19d ago
Apr 1st, 2026
Sublime Security
MalwareBazaar: Malicious attachment hash (trusted reporters)
25d ago
Mar 26th, 2026
Sublime Security
Link: Non-standard port 8443 in display URL
25d ago
Mar 26th, 2026
Sublime Security
Lookalike sender domain (untrusted sender)
26d ago
Mar 25th, 2026
Sublime Security
Attachment: ZIP file with CVE-2026-0866 exploit
1mo ago
Mar 20th, 2026
Sublime Security
Link: Free file hosting with undisclosed recipients
1mo ago
Mar 19th, 2026
Sublime Security
Link: PDF display text with fake copyright claim template
1mo ago
Mar 18th, 2026
Sublime Security
Link: IPv4-mapped IPv6 address obfuscation
1mo ago
Mar 17th, 2026
Sublime Security
Attachment: ICS file with excessive custom properties
1mo ago
Mar 17th, 2026
Sublime Security
Link: Obfuscation via userinfo with suspicious indicators
1mo ago
Mar 13th, 2026
Sublime Security
Link: Commonly Abused Web Service redirecting to ZIP file
1mo ago
Mar 10th, 2026
Sublime Security
Link: Mixed case HTTPS protocol
1mo ago
Mar 9th, 2026
Sublime Security