Home / Companies / Sublime Security / Blog / Post Details
Content Deep Dive

Hidden credential phishing within EML attachments

Blog post from Sublime Security

Post Details
Date Published
Author
Aiden Mitchell
Word Count
395
Company Posts That Month
4
Language
English
Hacker News Points
-
Post removed?
No
Summary

Sublime's Attack Spotlight series aims to inform users about the email threat landscape by showcasing real attack samples, detailing adversary tactics and techniques, and explaining detection methods. One highlighted attack involves credential phishing via EML attachments in Microsoft 365 emails, where a malicious link is hidden within a fake Microsoft Teams invite. The attack process includes multiple redirects through an open redirect, a Cloudflare Turnstile CAPTCHA, and a fake Microsoft login page, with detection signals such as suspicious EML attachments, short message bodies, and originating from a virtual private server. Sublime's AI-powered detection engine effectively prevents such attacks by identifying key indicators like credential theft language and disposable infrastructure, offering free accounts with customizable threat handling to enhance email security.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
LLM 1 2,876 370 130 -20%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.