Attack Type: Spam

Spam refers to bulk, unsolicited messages, often promoting questionable offers, fake opportunities, or irrelevant content you never asked for. These messages typically ignore basic rules around consent and use shady tactics to sneak past filters, like misspelled words (“W1NNER,” “FREEBlE”) or fake brand names that look close to the real thing (“L0WES,” “C0STC0”).
You’ve probably seen examples: work-from-home schemes with unrealistic pay, miracle health products, SEO pitches warning about your website, or companies pushing “verified” contact lists. Some spam even pretends to be part of an ongoing thread by adding fake “RE:” or “FWD:” subject lines.
Even when the emails look polished or pass authentication checks, they’re often filled with misleading claims, fake urgency, or vague references to prior contact. While not always malicious, spam clutters inboxes, wastes time, and occasionally serves as a delivery method for more serious threats.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Service abuse: Kagoya.net-hosted domains sending English business lures
2h ago
Aug 27th, 2026
Sublime Security
Link: Fake RFP/bid reference number lure
2d ago
Aug 25th, 2026
Sublime Security
Attachment: Risk assessment PDF with inline image
2d ago
Aug 25th, 2026
Sublime Security
Spam: Spoofed Outlook mailer with unsubscribe and reference ID footer
6d ago
Aug 21st, 2026
Sublime Security
Evasion: Suspicious TLD link redirecting to Wikipedia
6d ago
Aug 21st, 2026
Sublime Security
Link: Telegraph-hosted content
8d ago
Aug 19th, 2026
Sublime Security
Spam: Cold outreach from Cloudflare-hosted newly registered domain
10d ago
Aug 17th, 2026
Sublime Security
Link: .su domain link redirection from new sender domains
14d ago
Aug 13th, 2026
Sublime Security
Brand impersonation: SendGrid
20d ago
Aug 7th, 2026
Sublime Security
Spam: Fake photo share
21d ago
Aug 6th, 2026
Sublime Security
Body: CSS Hidden text via clip-path
22d ago
Aug 5th, 2026
Sublime Security
Body: CSS zero-value calc() obfuscation
22d ago
Aug 5th, 2026
Sublime Security
Brand impersonation: SiriusXM
23d ago
Aug 4th, 2026
Sublime Security
Spam: Default Microsoft Exchange Online sender domain (onmicrosoft.com)
24d ago
Aug 3rd, 2026
Sublime Security
Spam: Large financial amount mention from newly registered sender domain
24d ago
Aug 3rd, 2026
Sublime Security
Spam: Suspicious toll-free phone number
1mo ago
Jul 27th, 2026
Sublime Security
Brand Impersonation: Shein
1mo ago
Jul 27th, 2026
Sublime Security
Spam: Website errors solicitation
1mo ago
Jul 27th, 2026
Sublime Security
Service abuse: Microsoft with suspicious indicators in subject
1mo ago
Jul 27th, 2026
Sublime Security
Brand impersonation: Anthropic/Claude with newly registered domain
1mo ago
Jul 24th, 2026
Sublime Security