Attack Type: Spam

Spam refers to bulk, unsolicited messages, often promoting questionable offers, fake opportunities, or irrelevant content you never asked for. These messages typically ignore basic rules around consent and use shady tactics to sneak past filters, like misspelled words (“W1NNER,” “FREEBlE”) or fake brand names that look close to the real thing (“L0WES,” “C0STC0”).
You’ve probably seen examples: work-from-home schemes with unrealistic pay, miracle health products, SEO pitches warning about your website, or companies pushing “verified” contact lists. Some spam even pretends to be part of an ongoing thread by adding fake “RE:” or “FWD:” subject lines.
Even when the emails look polished or pass authentication checks, they’re often filled with misleading claims, fake urgency, or vague references to prior contact. While not always malicious, spam clutters inboxes, wastes time, and occasionally serves as a delivery method for more serious threats.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Service abuse: Demio notifications with suspicious content patterns
22h ago
May 11th, 2026
Sublime Security
Service abuse: Microsoft with suspicious indicators in subject
5d ago
May 7th, 2026
Sublime Security
Spam: Website errors solicitation
5d ago
May 7th, 2026
Sublime Security
Service Abuse: Zoom with freemail reply-to and recipient address in greeting
6d ago
May 6th, 2026
Sublime Security
Link: Romance/Sexual Language With Suspicious Link
7d ago
May 5th, 2026
Sublime Security
Service abuse: Zoom with newly registered reply-to domain
8d ago
May 4th, 2026
Sublime Security
Link: Google Calendar invite linking to an open redirect from an untrusted freemail sender
14d ago
Apr 28th, 2026
Sublime Security
Attachment: Calendar invite with suspicious link leading to an open redirect
14d ago
Apr 28th, 2026
Sublime Security
BEC/Fraud: Urgent language and suspicious sending/infrastructure patterns
25d ago
Apr 17th, 2026
Sublime Security
Attachment: Cold outreach with invitation subject and not attachment
1mo ago
Apr 3rd, 2026
Sublime Security
Service abuse: Google Firebase sender address with suspicious content
1mo ago
Apr 2nd, 2026
Sublime Security
Targeting: Specific AOL address
1mo ago
Mar 31st, 2026
Sublime Security
Spam: Fake dating profile notification
1mo ago
Mar 20th, 2026
Sublime Security
Service abuse: Domains By Proxy sender
1mo ago
Mar 18th, 2026
Sublime Security
Body HTML: Comment with 24-character hex token
1mo ago
Mar 17th, 2026
Sublime Security
Sender: IP address in local part
2mo ago
Mar 12th, 2026
Sublime Security
Brand impersonation: SendGrid
2mo ago
Mar 12th, 2026
Sublime Security
Spam: Sexually explicit content with emoji in subject from freemail provider
2mo ago
Mar 10th, 2026
Sublime Security
Link: Blogspot hosting explicit romance content
2mo ago
Mar 9th, 2026
Sublime Security
Headers: risky-recover-production message ID
2mo ago
Feb 26th, 2026
Sublime Security