Attack spotlight

November 21, 2025
Attack spotlight

You’ve been invited to join a Meta for Business scam!

You’ve been invited to join a Meta for Business scam!
Luke Wescott
Detection
You’ve been invited to join a Meta for Business scam!
group
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
November 21, 2025
Attack spotlight

You’ve been invited to join a Meta for Business scam!

Luke Wescott
Detection
November 13, 2025
Attack spotlight

Salesforce infrastructure abuse: Stopping email scams and spam sent via SFDC

Brandon Murphy
Detection
November 3, 2025
Attack spotlight

ICS phishing: Stopping a surge of malicious calendar invites

Ahry Jeon
Product Manager
Brandon Murphy
Detection
October 23, 2025
Attack spotlight

Direct Send abuse on Microsoft 365: Just another failed authentication

Peter Djordjevic
Detection
October 16, 2025
Attack spotlight

Facebook credential phishing with job scams impersonating well-known companies

Bryan Campbell
Detection
October 14, 2025
Attack spotlight

Google Careers impersonation credential phishing scam with endless variation

Brandon Murphy
Detection
October 8, 2025
Attack spotlight

UK Home Office visa & immigration scam targets Sponsor Management System accounts

Bryan Campbell
Detection
October 2, 2025
Attack spotlight

Impersonated Evite and Punchbowl invitations used for credential phishing and malware distribution

Brandon Webster
Detection
Bryan Campbell
Detection
September 23, 2025
Attack spotlight

Fake Meta Ads Manager in App Store and TestFlight used to phish Meta ad accounts

Brandon Webster
Detection
Threat Research Team
Sublime
September 4, 2025
Attack spotlight

Callback phishing with online appointment abuse and distribution lists

Brandon Webster
Detection
July 31, 2025
Attack spotlight

Multi-RMM attack: Splashtop Streamer and Atera payloads delivered via Discord CDN link

Josh "Soup" Campbell
Detection
Brandon Murphy
Detection
July 17, 2025
Attack spotlight

Phishing for Xfinity credentials with malicious Zoom Docs

Brandon Webster
Detection
July 2, 2025
Attack spotlight

Living Off Trusted Sites: Zoom service abuse to deliver credential phishing attack

Josh "Soup" Campbell
Detection
June 25, 2025
Attack spotlight

Using the X/Twitter link shortener (t.co) to hide an AITM credential phishing payload

Brandon Webster
Detection
June 12, 2025
Attack spotlight

AITM phishing with Russian infrastructure and detection evasion from a lapsed domain

Brandon Murphy
Detection
Threat Research Team
Sublime
May 29, 2025
Attack spotlight

Detecting an email-based ClickFix attack that delivers DCRat malware payload

Josh "Soup" Campbell
Detection
Brandon Murphy
Detection
May 8, 2025
Attack spotlight

ScreenConnect as malware via Canva abuse and Docusign impersonation

Brian Baskin
Threat Research
Brandon Webster
Detection
April 30, 2025
Attack spotlight

Figma abuse from compromised vendor used in credential theft attack

Sam Scholten
Detection
April 3, 2025
Attack spotlight

$500K financial fraud built on BEC, a domain lookalike, and a fake thread

Sam Scholten
Detection
April 1, 2025
Attack spotlight

Who are you trying to April Fool with that email scam?

Threat Detection Team
Sublime
March 27, 2025
Attack spotlight

Tycoon 2FA credential phishing with cloned internal employee login

Peter Djordjevic
Detection
March 20, 2025
Attack spotlight

Microsoft OAuth URL used as redirect to AITM credential phishing site

Brandon Murphy
Detection
March 13, 2025
Attack spotlight

Seeing both sides of a service abuse financial fraud using YOPmail disposable messages

Josh "Soup" Campbell
Detection
March 6, 2025
Attack spotlight

Base64-encoding an SVG attack within an iframe and hiding it all in an EML attachment

Sam Scholten
Detection
Brandon Murphy
Detection
February 25, 2025
Attack spotlight

Scripting Vector Grifts: SVG phishing with smuggled JS and adversary in the middle tactics

Brandon Murphy
Detection
Brandon Webster
Detection
February 18, 2025
Attack spotlight

Tax season email attacks: AdWind RATs and Tycoon 2FA phishing kits

Brandon Webster
Detection
Brandon Murphy
Detection
January 29, 2025
Attack spotlight

Credential phishing Charles Schwab account holders with 2FA bypass

Aiden Mitchell
Detection
January 7, 2025
Attack spotlight

Hiding a $50,000 BEC financial fraud in a fake email thread

Sam Scholten
Detection
December 19, 2024
Attack spotlight

Callback phishing via invoice abuse and distribution list relays

Brandon Murphy
Detection
December 17, 2024
Attack spotlight

B2B freight-forwarding scams on the rise to evade financial fraud crackdowns

Sam Scholten
Detection
November 27, 2024
Attack spotlight

Talking phish over turkey

Brandon Murphy
Detection
Aiden Mitchell
Detection
November 20, 2024
Attack spotlight

Hidden credential phishing within EML attachments

Aiden Mitchell
Detection
November 14, 2024
Attack spotlight

Living Off the Land: Credential Phishing via Docusign abuse

Brandon Murphy
Detection
November 6, 2024
Attack spotlight

Living Off the Land: Callback Phishing via Docusign comment

Brandon Murphy
Detection
October 30, 2024
Attack spotlight

Adversarial ML: Extortion via LLM Manipulation Tactics

Threat Detection Team
Sublime
August 30, 2024
Attack spotlight

Payroll Fraud via LLM-Generated Emails

Threat Detection Team
Sublime
July 2, 2024
Attack spotlight

Abusing Discord to deliver Agent Tesla malware

Threat Detection Team
Sublime
June 26, 2024
Attack spotlight

Fake invoice used to conduct $16,800 BEC attempt

Threat Detection Team
Sublime
March 30, 2023
Attack spotlight

Detecting Credential Phishing using Deep Learning + MQL

Bobby Filar
Machine Learning
Item not found

No Results Found

Oops! No Blog found for this category.

Now is the time.

See how Sublime delivers autonomous protection by default, with control on demand.

BG Pattern