Home / Companies / Sublime Security / Blog / July 2025

July 2025 Summaries

4 posts from Sublime Security

Filter
Month: Year:
Post Summaries Back to Blog
Sublime's Attack Spotlight series highlights real-world email threats, focusing on adversary tactics, techniques, and detection methods, with a specific case involving Microsoft 365 and malware/ransomware attacks via Remote Monitoring and Management (RMM) software. In a recent attack, a compromised email account was used to distribute a malicious payload that impersonated OneDrive, tricking recipients into downloading a file that appeared to be a .docx but was actually a .msi installer for RMM tools like Atera and Splashtop, allowing attackers to maintain remote access. This attack was detected and thwarted by Sublime's AI-powered detection engine, which identified key signals such as file extension manipulation and the use of free file hosting via Discord CDN. The series emphasizes the importance of adaptive email security platforms that leverage AI and machine learning to identify subtle threats, helping prevent malicious installers from reaching inboxes.
Jul 31, 2025 600 words in the original blog post.
Sublime has uncovered a cyberattack campaign targeting German speakers using a romance or adult-themed scam that employs Keitaro Traffic Distribution Service (TDS) to deliver malware. The attack leverages explicit emails containing links to malicious domains, which redirect users to a 300MB ISO file from a Russian host. This file employs a known counter-analysis technique by increasing its size to avoid detection by security platforms and contains an executable and a password-protected text file. Upon execution, the malware extracts and runs multiple files, creating explicit images and dropping additional files into the user's temporary directory. The attack uses a batch script with obfuscation and junk data to manipulate variables and execute logic branches, ultimately constructing an AutoIt interpreter to run a custom, heavily obfuscated script. This script creates a Windows scheduled task to ensure persistent execution of the malware. Sublime's detection engine identified the attack through various indicators, including romance scam elements, suspicious email origins, and password-protected archives. The attack shares similarities with the Rhadamanthys Infostealer and a known malvertising campaign.
Jul 24, 2025 1,532 words in the original blog post.
Sublime's Attack Spotlight series aims to inform readers about the email threat landscape by showcasing real-world attack samples, detailing adversary tactics and techniques, and explaining detection methods. A recent attack involved credential phishing targeting Microsoft users by impersonating Xfinity customer service, using email tactics like misspellings and urgent language to evade detection. The attack began with an email from a Gmail address masquerading as Xfinity's "Customer Services Team," urging users to update their accounts via a misleading Zoom Doc link. This email contained subtle signs of deception, such as domain mismatches and filter evasion strategies. Sublime's AI-driven detection engine and machine learning-powered Link Analysis were instrumental in identifying and preventing this attack. The series underscores the importance of adaptive email security platforms that utilize AI and machine learning to detect LOTS (Living off Trusted Sites) attacks, which exploit trusted domains for malicious purposes.
Jul 17, 2025 549 words in the original blog post.
Sublime's Attack Spotlight series highlights the evolving email threat landscape by showcasing real-world attack samples and explaining adversary tactics, with a focus on a recent credential phishing attack using Zoom's platform. This particular attack exploited Zoom Events and Zoom Docs to deliver a phishing payload that mimicked a Microsoft Office 365 portal, ultimately leading unsuspecting users to a fake Microsoft login page to steal credentials. Sublime's AI-powered detection engine successfully prevented the attack by identifying suspicious signs such as vague language, unnamed senders, and credential theft indicators. The series emphasizes the importance of adaptive, AI-driven email security solutions to detect and prevent attacks that leverage trusted sites.
Jul 02, 2025 521 words in the original blog post.