Attack Type: Malware/Ransomware

Malware and Ransomware attacks are designed to infect your system through things like fake invoices, password-protected attachments, or files disguised as routine business documents. Once opened, they quietly install malicious software that can steal data, encrypt files, or open the door for more serious threats.
You might see things like macro-enabled Office documents, HTML attachments, or ZIP files that require a password. These are tricks to get around email filters and convince you to interact. Once the malware runs, it can connect to attacker-controlled servers, spread across your network, and even bring in more payloads.
Ransomware is especially damaging. It locks up your files and demands a payment—usually in cryptocurrency—to get them back. Some attackers also steal data and threaten to leak it if the ransom isn’t paid, a tactic known as double extortion. The impact can be severe, including downtime, lost data, financial loss, and reputational damage.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Attachment: SVG files with evasion elements
4d ago
May 8th, 2026
Sublime Security
Observed IOC: Malicious domains in body links
5d ago
May 7th, 2026
Sublime Security
Observed IOC: Malicious sender email addresses
5d ago
May 7th, 2026
Sublime Security
Observed IOC: Malicious sender domains
5d ago
May 7th, 2026
Sublime Security
Observed IOC: Malicious sender root domains
8d ago
May 4th, 2026
Sublime Security
Attachment: PDF with suspicious HeadlessChrome metadata
11d ago
May 1st, 2026
Sublime Security
Attachment: QR code with userinfo portion
12d ago
Apr 30th, 2026
Sublime Security
Attachment with unscannable encrypted zip
12d ago
Apr 30th, 2026
Sublime Security
Adobe branded PDF file linking to a password-protected file from untrusted sender
13d ago
Apr 29th, 2026
Sublime Security
MalwareBazaar: Malicious attachment hash in archive (trusted reporters)
13d ago
Apr 29th, 2026
Sublime Security
Attachment: ICS with embedded Javascript in SVG file
14d ago
Apr 28th, 2026
Sublime Security
Attachment: ICS file with excessive custom properties
14d ago
Apr 28th, 2026
Sublime Security
Attachment: ICS file with AWS Lambda URL
14d ago
Apr 28th, 2026
Sublime Security
Attachment: HTML smuggling with atob and high entropy via calendar invite
14d ago
Apr 28th, 2026
Sublime Security
Attachment: HTML smuggling with eval and atob via calendar invite
14d ago
Apr 28th, 2026
Sublime Security
Attachment: Calendar file with invisible Unicode characters
14d ago
Apr 28th, 2026
Sublime Security
Attachment: ICS with embedded document
14d ago
Apr 28th, 2026
Sublime Security
CVE-2023-5631 - Roundcube Webmail XSS via crafted SVG
15d ago
Apr 27th, 2026
Sublime Security
Attachment: Double base64-encoded zip file in HTML smuggling attachment
15d ago
Apr 27th, 2026
@ajpc500
Attachment: File execution via Javascript
15d ago
Apr 27th, 2026
Sublime Security