March 2025 Summaries
4 posts from Sublime Security
Filter
Month:
Year:
Post Summaries
Back to Blog
Sublime's Attack Spotlight series highlights real-world email threats and the methods used by adversaries, such as the Tycoon 2FA phishing-as-a-service (PhaaS) attacks targeting Microsoft 365 users with credential phishing schemes. These attacks often employ adversary-in-the-middle (AITM) tactics to mimic legitimate company login pages, leveraging tools and templates sold by PhaaS providers to rapidly create and modify phishing campaigns. A recently detected attack used a seemingly innocuous email about updated employee policies, which included a PDF with a QR code leading to a fake login page designed to steal user credentials. Sublime's AI-powered detection engine identified and thwarted this attack by recognizing signals like suspicious QR codes, blank email bodies, and newly registered sender domains. The series emphasizes the importance of adaptive email security platforms that utilize AI and machine learning to counter evolving phishing strategies.
Mar 27, 2025
702 words in the original blog post.
Sublime's Attack Spotlight series highlights the evolving email threat landscape by showcasing real-world attack samples, describing adversary tactics, and explaining detection methods, with an emphasis on credential phishing attacks using Microsoft 365. These attacks cleverly use legitimate Microsoft OAuth URLs to disguise malicious activities, such as redirecting users to a fake Microsoft login page after a false password reset message. This technique, part of a suspected international campaign, takes advantage of users' trust in familiar brands, like Adobe, by requesting minimal app permissions that appear harmless but lead to credential theft. Sublime's AI-powered detection engine identifies these threats through signals like suspicious Office 365 app authorization links and messages from previously unknown senders. The platform offers a free account for detecting and preventing such email-based threats, providing customizable solutions for different environments.
Mar 20, 2025
632 words in the original blog post.
Sublime's Attack Spotlight series aims to educate readers about the email threat landscape by presenting real-life attack examples, adversary tactics, and detection methods, emphasizing the prevention of such threats with a free Sublime account. A recent focus is on a callback phishing attack using Google Workspace, where a distribution list relay facilitates the spread of fraudulent invoices with a "helpline number" intended to lure targets into further interaction. The novelty of this attack lies in the use of a YOPmail reply-to address, which is a disposable email service allowing public access to its inboxes without a password. The attacker exploited a free Adobe Creative Cloud trial to send signing requests via a configured distribution list, demonstrating how easily multiple free services can be abused to accelerate attack campaigns. Sublime's AI-powered detection engine identified key signals of this attack, such as messages from unknown domains and suspicious document notifications, effectively preventing it. Users are encouraged to create a free Sublime account for comprehensive protection against such threats.
Mar 13, 2025
659 words in the original blog post.
Sublime's Attack Spotlight series sheds light on the evolving email threat landscape by presenting real-world attack samples, such as a credential phishing attack targeting Microsoft 365 users. This particular attack leveraged an EML attachment containing a malicious SVG file that was disguised as a voicemail recording, which when opened, redirected the victim to a fake Microsoft login page. The attack used multiple layers of evasion, including base64 encoding and custom obfuscation, to avoid detection. Sublime's platform introduced new features to counter such threats, including the beta.scan_base64 function, which decodes encoded strings to identify hidden malicious content. The company's AI-powered detection engine flagged the attack as malicious based on signals like EML attachments, SVG files with iframes, and base64 encoding. The detailed analysis and de-obfuscation efforts highlighted the attackers' sophisticated techniques and underscored the importance of protecting login credentials.
Mar 06, 2025
848 words in the original blog post.