Attack Type: Malware/Ransomware

Malware and Ransomware attacks are designed to infect your system through things like fake invoices, password-protected attachments, or files disguised as routine business documents. Once opened, they quietly install malicious software that can steal data, encrypt files, or open the door for more serious threats.
You might see things like macro-enabled Office documents, HTML attachments, or ZIP files that require a password. These are tricks to get around email filters and convince you to interact. Once the malware runs, it can connect to attacker-controlled servers, spread across your network, and even bring in more payloads.
Ransomware is especially damaging. It locks up your files and demands a payment—usually in cryptocurrency—to get them back. Some attackers also steal data and threaten to leak it if the ransom isn’t paid, a tactic known as double extortion. The impact can be severe, including downtime, lost data, financial loss, and reputational damage.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Observed IOC: Malicious sender email addresses
4d ago
May 29th, 2026
Sublime Security
Link: Numeric IP obfuscation in URL
5d ago
May 28th, 2026
Sublime Security
Observed IOC: Malicious root domains in body links
6d ago
May 27th, 2026
Sublime Security
Observed IOC: Malicious sender domains
6d ago
May 27th, 2026
Sublime Security
Image as content with a link to an open redirect
7d ago
May 26th, 2026
Sublime Security
Attachment: SVG file with HTML entity encoded href attributes
13d ago
May 20th, 2026
Sublime Security
Observed IOC: Malicious domains in body links
14d ago
May 19th, 2026
Sublime Security
Observed IOC: Malicious URLs in body links
14d ago
May 19th, 2026
Sublime Security
Brand impersonation: Paperless Post
15d ago
May 18th, 2026
Sublime Security
Attachment: Embedded VBScript in MHT file
19d ago
May 14th, 2026
Sublime Security
Attachment: Microsoft impersonation via PDF with link and suspicious language
19d ago
May 14th, 2026
Sublime Security
Attachment: SVG files with evasion elements
25d ago
May 8th, 2026
Sublime Security
Observed IOC: Malicious sender root domains
29d ago
May 4th, 2026
Sublime Security
Attachment: PDF with suspicious HeadlessChrome metadata
1mo ago
May 1st, 2026
Sublime Security
Attachment with unscannable encrypted zip
1mo ago
Apr 30th, 2026
Sublime Security
Attachment: QR code with userinfo portion
1mo ago
Apr 30th, 2026
Sublime Security
Adobe branded PDF file linking to a password-protected file from untrusted sender
1mo ago
Apr 29th, 2026
Sublime Security
MalwareBazaar: Malicious attachment hash in archive (trusted reporters)
1mo ago
Apr 29th, 2026
Sublime Security
Attachment: ICS with embedded document
1mo ago
Apr 28th, 2026
Sublime Security
Attachment: ICS file with excessive custom properties
1mo ago
Apr 28th, 2026
Sublime Security