April 2025 Summaries
8 posts from Sublime Security
Filter
Month:
Year:
Post Summaries
Back to Blog
Sublime's Attack Spotlight series highlights the evolving threat landscape of email attacks, focusing on real-world examples, adversary tactics, and detection methods, with an emphasis on credential phishing attacks leveraging Living Off Trusted Service (LOTS) techniques. Recent attacks have utilized design tools like Figma and Canva, capitalizing on their trusted status in business environments to bypass link scanning and deliver multistage phishing payloads. A specific incident involved a compromised vendor email account sending a message with a Figma file link, which directed targets to a fake Microsoft login page to steal credentials. Sublime's AI-powered detection engine, including the Autonomous Security Analyst (ASA), successfully identified and prevented this attack using signals like self-sender patterns, references to multiple sharing platforms, and suspicious subject lines. The series underscores the importance of adaptive email security platforms that employ AI and machine learning to detect subtle discrepancies in order to mitigate these increasingly popular LOTS attacks.
Apr 30, 2025
475 words in the original blog post.
Sublime's first Email Threat Research Report reveals a significant rise in sophisticated email threats, emphasizing the growing prevalence of QR code and OAuth phishing, and the importance of adaptive detection strategies. The report, based on anonymized customer data and strict privacy protocols, highlights a 40-60% increase in QR code phishing and a dramatic 47,000% surge in SVG-based attacks in Q1 2025. It also notes a rise in Living Off Trusted Sites (LOTS) attacks using services like Microsoft 365 and Google Workspace, and an uptick in AI-generated content for BEC/fraud campaigns. The findings suggest a shift away from mass, template-driven phishing to more tailored, automated attacks that evade static defenses, with 90% of malicious emails customized for their targets. Emerging threats and evolving evasion techniques, such as "evasion stacking," necessitate a layered, adaptive defense incorporating AI, machine learning, and behavioral analysis. As attackers refine their methods, security platforms like Sublime are adapting by analyzing detection signals in real time, offering proactive coverage without needing manual updates.
Apr 28, 2025
580 words in the original blog post.
ASA, the Autonomous Security Analyst, is designed to automate the process of investigating and resolving user-reported phishing emails, addressing the challenges faced by security teams overwhelmed by high volumes of reports. ASA functions as an AI-powered security expert that automatically analyzes, triages, and remediates messages, providing consistent verdicts and reducing the need for manual reviews by security analysts. It intelligently groups similar messages to manage large-scale phishing campaigns and offers customizable actions based on its analysis, including quarantining malicious content. For security managers with limited resources, ASA offers a cost-effective solution by improving response times and reducing the burden on undersized teams. While it operates in active or passive mode to allow assessment of its effectiveness, ASA maintains privacy by ensuring no customer data is shared with third-party providers. This tool provides a top-level view of its activities through the Sublime Enterprise platform, aiming to make security teams more proactive and efficient in managing email threats.
Apr 23, 2025
536 words in the original blog post.
Andrew Becherer has joined Sublime as the Chief Information Security Officer (CISO), bringing over two decades of experience in cybersecurity, infrastructure, and software assurance. Known for his technical expertise and strategic vision, Andrew has previously held significant roles, including as the first security hire at Datadog, where he established a robust security organization and led its security efforts through the company's hypergrowth and IPO. He later shaped the security strategy at Iterable, protecting data for influential consumer brands, and co-founded Staris AI to innovate in application security within the AI landscape. Andrew is also an advisor to cybersecurity startups and a prominent speaker at industry conferences such as Black Hat and RSA, and he views his new role at Sublime as a continuation of his dedication to safeguarding people, data, and systems in the digital age.
Apr 21, 2025
311 words in the original blog post.
Sublime has announced a new partnership with Elastic to enhance email security through open and transparent collaboration, allowing for seamless integration of Sublime's security data into Elastic's platform. This partnership enables teams to ingest and analyze email security data from Sublime using Elastic's tools, including two specific data streams: Message Event and Email Message, alongside additional visualizations and dashboards in Kibana. Elastic's open detection rules and Event Query Language (EQL) facilitate the correlation of email data with other security information, such as endpoint and network telemetry, providing a comprehensive security overview. The integration also includes an Audit data stream to track significant configuration changes within Sublime, with customizable options for alerts and visualizations, making Sublime a pivotal component of a holistic security strategy when combined with Elastic's capabilities.
Apr 17, 2025
749 words in the original blog post.
TROX Stealer is a sophisticated information-stealing malware operating as a Malware as a Service (MaaS), designed to exfiltrate sensitive data like credit card details and browser credentials from everyday users rather than enterprise networks. Initially detected by Sublime's Threat Research team in December 2024, this malware leverages urgent phishing emails to deliver its payload, often disguised under the guise of legal or debt-related communications. The malware employs a complex delivery and execution chain utilizing Python, Node.js, and WebAssembly to obfuscate its activities and evade detection. Despite its advanced evasion techniques, the core stealing functionalities rely on commonplace methods, such as querying application databases, making it detectable through various indicators of compromise (IOCs). The attackers have maintained a methodical infrastructure, updating certificates and utilizing domains like debt-collection-experts[.]com, and deploying the final payload via platforms like GitHub. Sublime's AI-powered detection system has developed rules to identify and prevent such threats, emphasizing the importance of recognizing urgent messages and suspicious links as potential red flags.
Apr 10, 2025
2,586 words in the original blog post.
Sublime's Attack Spotlight series highlights real-world email threats, including a sophisticated business email compromise (BEC) and fraud attempt involving vendor impersonation detected using Sublime's AI-powered detection engine. In this case, the attacker targeted a $500K invoice payment by fabricating a realistic-looking email thread using intelligence from a previous compromise, coupled with a lookalike domain, ascentshvac[.]com, to impersonate a real company, Ascent Inc. The fraudulent email requested confirmation of updated ACH banking details, creating a sense of urgency and trust through the use of legitimate branding and invoice details. Key detection signals included the newly registered lookalike domain, the absence of prior contact from the sender's domain with the receiving company, and the urgent request to change a payment destination. The series emphasizes the importance of AI and machine learning in spotting minor discrepancies that can indicate phishing attacks and encourages readers to stay informed through their blog and newsletter.
Apr 03, 2025
687 words in the original blog post.
Sublime's Detection team highlights both the serious and amusing aspects of email scams, noting that while some scams are laughably poorly crafted, others exploit vulnerabilities such as fear, economic need, or goodwill to deceive recipients. They describe various scam tactics, including impersonating celebrities, fake lotteries, and phishing attempts, often employing humor to underline the absurdity of some attempts. However, the team emphasizes the increasing sophistication of email scams due to new tools and techniques like AI and Phishing as a Service (PhaaS), which allow scammers to launch highly-targeted attacks at unprecedented speed and scale, outpacing traditional security systems. To counter these threats, effective email security platforms must adapt by utilizing AI and machine learning to anticipate and neutralize evolving tactics. Sublime encourages readers to explore their Attack Spotlights for more detailed insights into current phishing methods.
Apr 01, 2025
627 words in the original blog post.