Home / Companies / Sublime Security / Blog / May 2025

May 2025 Summaries

3 posts from Sublime Security

Filter
Month: Year:
Post Summaries Back to Blog
Sublime's Attack Spotlight series highlights a sophisticated email threat involving a malware attack delivered through a fake email thread about an apartment rental. The attacker used social engineering tactics by fabricating a scenario with a sick colleague to prompt the recipient to engage with a malicious link masquerading as a Booking.com "Accommodation Rules" page. This link led to a deceptive CAPTCHA that surreptitiously copied a malicious PowerShell command to the user's clipboard, which, if executed, would download and run a DCRat malware payload. The DCRat malware, a well-documented .Net-based remote access trojan, is capable of executing shell commands, keylogging, and stealing files, among other functions. Sublime's AI-powered detection engine successfully flagged and prevented the attack by identifying key signals such as newly registered domains, brand impersonation, and social engineering tactics. The series emphasizes the importance of adaptive email security platforms that utilize AI and machine learning to detect and prevent evolving threats.
May 29, 2025 898 words in the original blog post.
Sublime has introduced ASA, an Autonomous Security Analyst that utilizes a security-specific language model to autonomously handle email threat triage, remediation, and communication, thereby reducing mean time to respond without increasing workforce size. ASA, praised for transforming manual review processes from days to minutes, employs a proprietary knowledge base and a suite of analytical tools to conduct comprehensive threat assessments, mirroring human analysts' capabilities. It uses subagents for parallel task execution, enhancing efficiency and adaptability in complex scenarios, while maintaining transparency with citation-backed verdicts. ASA operates under a privacy-first architecture, ensuring data security by not retaining raw email content and allowing users to choose deployment models. Future enhancements include advanced link exploration and the ability to integrate organization-specific security policies. ASA exemplifies Sublime's open security philosophy by combining agentic AI with an accessible toolset, promoting human-AI collaboration in email security.
May 15, 2025 1,573 words in the original blog post.
Sublime's Attack Spotlight series highlights a recent increase in email threats leveraging Canva to distribute malware and conduct credential phishing. These attacks exploit Canva's trusted reputation and ease of use, allowing perpetrators to create seemingly legitimate pages for malicious purposes. The series reports that some campaigns use fake CAPTCHA pages with encrypted JavaScript to evade detection tools, redirecting users to phishing sites for services like Google and Xfinity. Other attacks involve directing victims to download ScreenConnect remote administration software by impersonating brands through Canva-hosted pages. Though ScreenConnect is a legitimate tool, attackers manipulate its configuration to connect to malicious servers. Sublime's AI detection engine identifies such threats by recognizing brand impersonation and mass distribution tactics, helping organizations preemptively block these sophisticated email-based attacks.
May 08, 2025 1,527 words in the original blog post.