Attack Type: Spam

Spam refers to bulk, unsolicited messages, often promoting questionable offers, fake opportunities, or irrelevant content you never asked for. These messages typically ignore basic rules around consent and use shady tactics to sneak past filters, like misspelled words (“W1NNER,” “FREEBlE”) or fake brand names that look close to the real thing (“L0WES,” “C0STC0”).
You’ve probably seen examples: work-from-home schemes with unrealistic pay, miracle health products, SEO pitches warning about your website, or companies pushing “verified” contact lists. Some spam even pretends to be part of an ongoing thread by adding fake “RE:” or “FWD:” subject lines.
Even when the emails look polished or pass authentication checks, they’re often filled with misleading claims, fake urgency, or vague references to prior contact. While not always malicious, spam clutters inboxes, wastes time, and occasionally serves as a delivery method for more serious threats.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Brand impersonation: SendGrid
5d ago
Aug 7th, 2026
Sublime Security
Spam: Fake photo share
6d ago
Aug 6th, 2026
Sublime Security
Body: CSS zero-value calc() obfuscation
7d ago
Aug 5th, 2026
Sublime Security
Body: CSS Hidden text via clip-path
7d ago
Aug 5th, 2026
Sublime Security
Spam: Cold outreach from Cloudflare-hosted newly registered domain
8d ago
Aug 4th, 2026
Sublime Security
Brand impersonation: SiriusXM
8d ago
Aug 4th, 2026
Sublime Security
Spam: Default Microsoft Exchange Online sender domain (onmicrosoft.com)
9d ago
Aug 3rd, 2026
Sublime Security
Spam: Large financial amount mention from newly registered sender domain
9d ago
Aug 3rd, 2026
Sublime Security
Spam: Suspicious toll-free phone number
16d ago
Jul 27th, 2026
Sublime Security
Brand Impersonation: Shein
16d ago
Jul 27th, 2026
Sublime Security
Spam: Website errors solicitation
16d ago
Jul 27th, 2026
Sublime Security
Service abuse: Microsoft with suspicious indicators in subject
16d ago
Jul 27th, 2026
Sublime Security
Brand impersonation: Anthropic/Claude with newly registered domain
19d ago
Jul 24th, 2026
Sublime Security
Message content: Request for author engagement
19d ago
Jul 24th, 2026
Sublime Security
Service abuse: Zohodesk reply-to mismatch with job scam indicators
21d ago
Jul 22nd, 2026
Sublime Security
Service abuse: Zoom Clips with unregistered reply-to domain
26d ago
Jul 17th, 2026
Sublime Security
Attachment: Romance scam with image lure and advance-fee or suspicious link indicators
1mo ago
Jul 1st, 2026
Sublime Security
Link: Google Cloud Storage redirect to external domain
1mo ago
Jun 30th, 2026
Sublime Security
Link: Google Cloud Storage with short-path link delivery
1mo ago
Jun 30th, 2026
Sublime Security
Link: Suspicious single-domain link with suspicious path and financial lure indicators
1mo ago
Jun 26th, 2026
Sublime Security