Attack Type: Spam

Spam refers to bulk, unsolicited messages, often promoting questionable offers, fake opportunities, or irrelevant content you never asked for. These messages typically ignore basic rules around consent and use shady tactics to sneak past filters, like misspelled words (“W1NNER,” “FREEBlE”) or fake brand names that look close to the real thing (“L0WES,” “C0STC0”).
You’ve probably seen examples: work-from-home schemes with unrealistic pay, miracle health products, SEO pitches warning about your website, or companies pushing “verified” contact lists. Some spam even pretends to be part of an ongoing thread by adding fake “RE:” or “FWD:” subject lines.
Even when the emails look polished or pass authentication checks, they’re often filled with misleading claims, fake urgency, or vague references to prior contact. While not always malicious, spam clutters inboxes, wastes time, and occasionally serves as a delivery method for more serious threats.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Link: Google Cloud Storage with echo-tail od= tracking token
4h ago
Oct 6th, 2026
Sublime Security
Link: Google Cloud Storage /index and /unsub link pair
4h ago
Oct 6th, 2026
Sublime Security
Link: Google Cloud Storage with prefixed base64 dash-record fragment
5h ago
Oct 6th, 2026
Sublime Security
Link: Google Cloud Storage with base64 go/sub-ID fragment
5h ago
Oct 6th, 2026
Sublime Security
Link: Google Cloud Storage with case-striped tracking token in fragment
5h ago
Oct 6th, 2026
Sublime Security
Link: Google Cloud Storage with suffixed unsubscribe bucket
5h ago
Oct 6th, 2026
Sublime Security
Link: Google Cloud Storage with short-path link delivery
5h ago
Oct 6th, 2026
Sublime Security
Spam: Fake photo share
4d ago
Oct 2nd, 2026
Sublime Security
Link: Romance/Sexual Language With Suspicious Link
7d ago
Sep 29th, 2026
Sublime Security
Attachment: Google share.google URL shortener in google.<tld>/share.google path form
8d ago
Sep 28th, 2026
Sublime Security
Attachment: ICS calendar invite with Google share.google URL shortener in google.<tld>/share.google path form
8d ago
Sep 28th, 2026
Sublime Security
Link: Google share.google URL shortener in google.<tld>/share.google path form
8d ago
Sep 28th, 2026
Sublime Security
Attachment: Calendar invite with suspicious link leading to an open redirect
8d ago
Sep 28th, 2026
Sublime Security
Mass campaign: Cross Site Scripting (XSS) attempt
8d ago
Sep 28th, 2026
Sublime Security
Link: Google Calendar invite linking to an open redirect from an untrusted freemail sender
8d ago
Sep 28th, 2026
Sublime Security
Encrypted Microsoft Office files from untrusted sender
8d ago
Sep 28th, 2026
Sublime Security
BEC/Fraud: B2B sales inquiry cold outreach lure
12d ago
Sep 24th, 2026
Sublime Security
Brand impersonation: Vanguard
13d ago
Sep 23rd, 2026
Sublime Security
Body: Embedded email headers indicative of thread hijacking/abuse
13d ago
Sep 23rd, 2026
Sublime Security
Spam: Ghostwriting services scam with manipulative language
13d ago
Sep 23rd, 2026
Sublime Security