Attack Type: Spam

Spam refers to bulk, unsolicited messages, often promoting questionable offers, fake opportunities, or irrelevant content you never asked for. These messages typically ignore basic rules around consent and use shady tactics to sneak past filters, like misspelled words (“W1NNER,” “FREEBlE”) or fake brand names that look close to the real thing (“L0WES,” “C0STC0”).
You’ve probably seen examples: work-from-home schemes with unrealistic pay, miracle health products, SEO pitches warning about your website, or companies pushing “verified” contact lists. Some spam even pretends to be part of an ongoing thread by adding fake “RE:” or “FWD:” subject lines.
Even when the emails look polished or pass authentication checks, they’re often filled with misleading claims, fake urgency, or vague references to prior contact. While not always malicious, spam clutters inboxes, wastes time, and occasionally serves as a delivery method for more serious threats.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Attachment: ICS calendar invite with Google share.google URL shortener in google.<tld>/share.google path form
2d ago
Sep 14th, 2026
Sublime Security
Attachment: Google share.google URL shortener in google.<tld>/share.google path form
2d ago
Sep 14th, 2026
Sublime Security
Link: Google share.google URL shortener in google.<tld>/share.google path form
2d ago
Sep 14th, 2026
Sublime Security
Spam: Fake photo share
5d ago
Sep 11th, 2026
Sublime Security
Link: Display text is 'unsb'
8d ago
Sep 8th, 2026
Sublime Security
Brand impersonation: MyChart
12d ago
Sep 4th, 2026
Sublime Security
Body: CSS Hidden text via table-column
13d ago
Sep 3rd, 2026
Sublime Security
Open redirect: Generic link.html redirector abuse
15d ago
Sep 1st, 2026
Sublime Security
Attachment: Fake research internship offer
15d ago
Sep 1st, 2026
Sublime Security
Body HTML: Comment with 24-character hex token
15d ago
Sep 1st, 2026
Sublime Security
Service abuse: Zoom Clips with suspicious reply-to address or links
15d ago
Sep 1st, 2026
Sublime Security
Link: Delimited encoded path parameters (~V~ scheme)
16d ago
Aug 31st, 2026
Sublime Security
Evasion: Variation selectors in subject line
19d ago
Aug 28th, 2026
Sublime Security
Link: Recently registered .vu domain in lure
19d ago
Aug 28th, 2026
Sublime Security
Service abuse: Kagoya.net-hosted domains sending English business lures
20d ago
Aug 27th, 2026
Sublime Security
Link: Fake RFP/bid reference number lure
22d ago
Aug 25th, 2026
Sublime Security
Attachment: Risk assessment PDF with inline image
22d ago
Aug 25th, 2026
Sublime Security
Spam: Spoofed Outlook mailer with unsubscribe and reference ID footer
26d ago
Aug 21st, 2026
Sublime Security
Evasion: Suspicious TLD link redirecting to Wikipedia
26d ago
Aug 21st, 2026
Sublime Security
Link: Telegraph-hosted content
28d ago
Aug 19th, 2026
Sublime Security