Home / Companies / Sublime Security / Blog / June 2025

June 2025 Summaries

3 posts from Sublime Security

Filter
Month: Year:
Post Summaries Back to Blog
Sublime's Attack Spotlight series sheds light on the evolving email threat landscape by analyzing real-world attack samples, which include adversary tactics and techniques, as well as detection methods. A notable attack in Q1 2025 utilized Twitter's t[.]co link shortener to disguise a credential phishing payload that impersonated a secure message notification from a "DocuSign-Account" via the edocs[.]com domain, incorporating language from Citrix ShareFile notifications. The email tricked recipients into clicking a link suggesting an encrypted financial message, which redirected them to a phishing page impersonating Adobe and Microsoft for credential harvesting. This attack was detected and prevented by Sublime's AI-powered detection engine, which flagged signals such as brand confusion, lookalike sender domains, link shortenings, and financial urgency—common tactics in LOTS (Living Off Trusted Sites) attacks. Sublime emphasizes the importance of adaptive email security platforms that utilize AI and machine learning to detect subtle discrepancies and protect against obfuscated threats.
Jun 25, 2025 504 words in the original blog post.
Sublime offers a unique approach to email security by providing open and modifiable AI-powered Detection Rules, allowing users to edit, test, and share these rules through an intuitive detection workbench without needing to submit support tickets. This collaborative framework encourages community contributions, enabling users to share rules for potential inclusion in Sublime's Core Feed or on the Sublime Community Slack for peer review. Highlighted community-contributed rules include detection of malicious Visual Studio Tools for Office add-ins embedded in Microsoft Office documents, identification of QakBot attacks using double Base64 encoded ZIP files in HTML attachments, and detection of ROT13-based obfuscation in HTML files, showcasing the platform's adaptability to evolving threats. By empowering users to contribute to and refine detection rules, Sublime promotes a collaborative environment that enhances security measures and broadens protection against email-based threats.
Jun 18, 2025 760 words in the original blog post.
Sublime's Attack Spotlight series highlights a sophisticated phishing campaign targeting Microsoft 365 users through a fake Microsoft Teams meeting invitation. The attack begins with a seemingly legitimate invitation email that redirects users to a phishing site instead of a Teams meeting. This campaign uses a complex infrastructure involving expired, repurposed domains, and obfuscation techniques to evade detection. It leverages a known domain, dilloncriminallaw.com, with previous legitimacy and a sophisticated multi-stage credential harvesting process. The phishing link includes a "gate" page that performs bot detection and browser fingerprinting to bypass security tools. If a user passes the checks, they are led through a series of obfuscated JavaScript stages designed to collect user credentials. The campaign uses various techniques to ensure its effectiveness, such as domain blocking, IP checks, and email encoding, while also employing advanced methods to avoid automated detection. Sublime's AI-powered detection engine, ASA, successfully flagged this attack using signals like sender domain mismatch and suspicious sender behavior, illustrating the importance of advanced detection tools in combating phishing threats.
Jun 12, 2025 3,134 words in the original blog post.