logo

Hidden credential phishing within EML attachments · Blog · Sublime Security

ID: 8cd3a54b-0c4e-5870-a32d-ff0a714f73c7

STIX ID: report--8cd3a54b-0c4e-5870-a32d-ff0a714f73c7

Feed Name: Sublime Security Blog

Threat Score
55/100

Date Published: 2025-10-22

Date Updated: 2026-05-01

...
...

Sublime's Attack Spotlight describes an in-the-wild credential-phishing campaign targeting Microsoft 365 users where malicious EML attachments render fake Teams meeting invites that redirect victims through an open redirect and Cloudflare Turnstile CAPTCHA to a spoofed Microsoft login page; the report details attack characteristics, detection signals (suspicious EML content, short body, VPS sender), and links to MQL detection rules used to block these messages.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.