Tactic or Technique: Scripting

Attackers use scripting languages like JavaScript, VBScript, and PowerShell to run malicious code delivered through phishing emails or compromised websites. These scripts can load hidden content, redirect you to phishing pages, or silently steal data in the background.
To avoid detection, attackers often scramble the code using encryption, compression, or multiple layers of encoding. This makes it harder for both security tools and analysts to understand what the script is doing.
Scripting is flexible and often used to fingerprint your browser, deliver customized payloads, or create a connection to an attacker-controlled server. Once that connection is active, the script can pull down more malware, collect sensitive information, or give an attacker continued access to your device.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
ClickFix: Clipboard hijack lure with copy-paste-to-terminal instruction
1d ago
Aug 26th, 2026
Sublime Security
Link: Credential phishing with obfuscated JavaScript redirect
6d ago
Aug 21st, 2026
Sublime Security
Link: Suspicious recipient with timeout redirect
23d ago
Aug 4th, 2026
Sublime Security
Credential theft: JavaScript date manipulation in HTML body
1mo ago
Jul 28th, 2026
Sublime Security
Attachment: Microsoft impersonation via PDF with link and suspicious language
3mo ago
May 14th, 2026
Sublime Security
Attachment: Embedded VBScript in MHT file
3mo ago
May 14th, 2026
Sublime Security
Suspected cross-site scripting (XSS) found in subject
3mo ago
May 4th, 2026
Sublime Security
Attachment: ICS with embedded Javascript in SVG file
4mo ago
Apr 28th, 2026
Sublime Security
Attachment: HTML smuggling with atob and high entropy via calendar invite
4mo ago
Apr 28th, 2026
Sublime Security
Attachment: HTML smuggling with eval and atob via calendar invite
4mo ago
Apr 28th, 2026
Sublime Security
CVE-2023-5631 - Roundcube Webmail XSS via crafted SVG
4mo ago
Apr 27th, 2026
Sublime Security
Attachment: File execution via Javascript
4mo ago
Apr 27th, 2026
Sublime Security
Attachment: Double base64-encoded zip file in HTML smuggling attachment
4mo ago
Apr 27th, 2026
@ajpc500
Link: Landing page with search-ms protocol redirect
4mo ago
Apr 7th, 2026
Sublime Security
Link: JavaScript obfuscation with Telegram bot integration
6mo ago
Feb 25th, 2026
Sublime Security
Attachment: cmd file extension
6mo ago
Feb 9th, 2026
Sublime Security
Attachment: HTML smuggling with setTimeout
7mo ago
Jan 12th, 2026
Sublime Security
Attachment: HTML smuggling 'body onload' with high entropy and suspicious text
7mo ago
Jan 12th, 2026
Sublime Security
Attachment: HTML smuggling with unescape
7mo ago
Jan 12th, 2026
Sublime Security
Attachment: LNK with embedded content
7mo ago
Jan 12th, 2026
@ajpc500