Attack Type: Malware/Ransomware

Malware and Ransomware attacks are designed to infect your system through things like fake invoices, password-protected attachments, or files disguised as routine business documents. Once opened, they quietly install malicious software that can steal data, encrypt files, or open the door for more serious threats.
You might see things like macro-enabled Office documents, HTML attachments, or ZIP files that require a password. These are tricks to get around email filters and convince you to interact. Once the malware runs, it can connect to attacker-controlled servers, spread across your network, and even bring in more payloads.
Ransomware is especially damaging. It locks up your files and demands a payment—usually in cryptocurrency—to get them back. Some attackers also steal data and threaten to leak it if the ransom isn’t paid, a tactic known as double extortion. The impact can be severe, including downtime, lost data, financial loss, and reputational damage.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Observed IOC: Malicious sender email addresses
1d ago
Sep 15th, 2026
Sublime Security
Spamhaus: Mail transiting an ASN-DROP listed network
1d ago
Sep 15th, 2026
Sublime Security
Spamhaus: Mail transiting a DROP listed network
2d ago
Sep 14th, 2026
Sublime Security
Attachment: PDF object hash cred phish
5d ago
Sep 11th, 2026
Sublime Security
Link: ScreenConnect remote access tool delivery with unattended guest access
5d ago
Sep 11th, 2026
Sublime Security
Attachment: XLS with legal confidentiality disclaimer
6d ago
Sep 10th, 2026
Sublime Security
Brand impersonation: Google Drive fake file share
6d ago
Sep 10th, 2026
Sublime Security
Attachment: PDF with EOF MD5 hash marker
6d ago
Sep 10th, 2026
Sublime Security
Body: CVE-2026-42897 Exchange OWA stored XSS
7d ago
Sep 9th, 2026
Sublime Security
Link: Fake video link from newly registered domain
8d ago
Sep 8th, 2026
Sublime Security
Observed IOC: Mail transiting OFAC-sanctioned bulletproof host Aeza Group
8d ago
Sep 8th, 2026
Sublime Security
Link: Numeric IP obfuscation in URL
8d ago
Sep 8th, 2026
Sublime Security
Attachment: ICS file with excessive custom properties
12d ago
Sep 4th, 2026
Sublime Security
Observed IOC: Malicious root domains in body links
12d ago
Sep 4th, 2026
Sublime Security
Observed IOC: Malicious domains in body links
12d ago
Sep 4th, 2026
Sublime Security
Observed IOC: Malicious URLs in body links
14d ago
Sep 2nd, 2026
Sublime Security
Brand impersonation: Paperless Post
16d ago
Aug 31st, 2026
Sublime Security
Attachment: ZIP filename mismatch
16d ago
Aug 31st, 2026
Sublime Security
Observed IOC: Malicious attachment SHA-256 hashes
19d ago
Aug 28th, 2026
Sublime Security
Observed IOC: Malicious sender domains
19d ago
Aug 28th, 2026
Sublime Security