Attack Type: Malware/Ransomware

Malware and Ransomware attacks are designed to infect your system through things like fake invoices, password-protected attachments, or files disguised as routine business documents. Once opened, they quietly install malicious software that can steal data, encrypt files, or open the door for more serious threats.
You might see things like macro-enabled Office documents, HTML attachments, or ZIP files that require a password. These are tricks to get around email filters and convince you to interact. Once the malware runs, it can connect to attacker-controlled servers, spread across your network, and even bring in more payloads.
Ransomware is especially damaging. It locks up your files and demands a payment—usually in cryptocurrency—to get them back. Some attackers also steal data and threaten to leak it if the ransom isn’t paid, a tactic known as double extortion. The impact can be severe, including downtime, lost data, financial loss, and reputational damage.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Observed IOC: Malicious sender email addresses
6h ago
Oct 6th, 2026
Sublime Security
Spamhaus: Mail transiting an ASN-DROP listed network
6h ago
Oct 6th, 2026
Sublime Security
Observed IOC: Malicious domains in body links
6h ago
Oct 6th, 2026
Sublime Security
Observed IOC: Mail transiting OFAC-sanctioned bulletproof host Aeza Group
6h ago
Oct 6th, 2026
Sublime Security
Spamhaus: Mail transiting a DROP listed network
6h ago
Oct 6th, 2026
Sublime Security
Observed IOC: Malicious root domains in body links
1d ago
Oct 5th, 2026
Sublime Security
Observed IOC: Malicious URLs in body links
4d ago
Oct 2nd, 2026
Sublime Security
Attachment: QR code with userinfo portion
8d ago
Sep 28th, 2026
Sublime Security
Attachment: Embedded Javascript in SVG file
8d ago
Sep 28th, 2026
Sublime Security
Mass campaign: Cross Site Scripting (XSS) attempt
8d ago
Sep 28th, 2026
Sublime Security
Encrypted Microsoft Office files from untrusted sender
8d ago
Sep 28th, 2026
Sublime Security
Observed IOC: Malicious sender domains
8d ago
Sep 28th, 2026
Sublime Security
Observed IOC: Mail transiting OFAC-sanctioned bulletproof host Media Land / ML Cloud
12d ago
Sep 24th, 2026
Sublime Security
Open redirect: bangkoksync.com
13d ago
Sep 23rd, 2026
Sublime Security
Brand impersonation: Google Drive fake file share
13d ago
Sep 23rd, 2026
Sublime Security
Brand impersonation: Vanguard
13d ago
Sep 23rd, 2026
Sublime Security
Open redirect: adnxs.com
13d ago
Sep 23rd, 2026
Sublime Security
Open redirect: agena-smile.com
13d ago
Sep 23rd, 2026
Sublime Security
Open redirect: museepicassoparis.fr
13d ago
Sep 23rd, 2026
Sublime Security
Open redirect: astroarts.co.jp
13d ago
Sep 23rd, 2026
Sublime Security