Skip to content

Create impersonate_hubspot_suspicious_content.yml#4277

Open
IndiaAce wants to merge 6 commits into
mainfrom
india.fn.ESC-8691.impersonate_hubspot
Open

Create impersonate_hubspot_suspicious_content.yml#4277
IndiaAce wants to merge 6 commits into
mainfrom
india.fn.ESC-8691.impersonate_hubspot

Conversation

@IndiaAce
Copy link
Copy Markdown
Member

@IndiaAce IndiaAce commented Mar 30, 2026

Description

Detects credential phishing attacks impersonating HubSpot by matching messages with "HubSpot" in the sender display name, HubSpot-specific content indicators (company name, addresses), and suspicious elements including QR codes, unsubscribe manipulation, or account reconnection/deactivation language.

Associated samples

Associated hunts

Screenshot (insights)

@IndiaAce IndiaAce requested a review from a team March 30, 2026 16:32
@IndiaAce IndiaAce requested a review from a team as a code owner March 30, 2026 16:32
@github-actions github-actions Bot added the in-test-rules PR is in our testing suite to collect telemetry label Mar 30, 2026
github-actions Bot added a commit that referenced this pull request Mar 30, 2026
github-actions Bot added a commit that referenced this pull request Mar 30, 2026
…n: HubSpot with QR code or suspicious content
github-actions Bot added a commit that referenced this pull request Apr 7, 2026
github-actions Bot added a commit that referenced this pull request Apr 7, 2026
…tion: HubSpot with QR code or suspicious content
github-actions Bot added a commit to IndiaAce/sublime-rules that referenced this pull request Apr 8, 2026
…on: HubSpot with QR code or suspicious content
github-actions Bot added a commit that referenced this pull request Apr 9, 2026
github-actions Bot added a commit to IndiaAce/sublime-rules that referenced this pull request Apr 9, 2026
…ation: HubSpot with QR code or suspicious content
github-actions Bot added a commit that referenced this pull request Apr 9, 2026
…tion: HubSpot with QR code or suspicious content
Comment thread detection-rules/impersonate_hubspot_suspicious_content.yml Outdated
@IndiaAce IndiaAce force-pushed the india.fn.ESC-8691.impersonate_hubspot branch from 05f5cf9 to 13b7c4d Compare May 18, 2026 15:25
@IndiaAce IndiaAce requested review from a team and cameron-dunn-sublime as code owners May 18, 2026 15:25
@IndiaAce IndiaAce force-pushed the india.fn.ESC-8691.impersonate_hubspot branch from a6ebbe3 to 19e9e6b Compare May 18, 2026 15:31
github-actions Bot added a commit that referenced this pull request May 18, 2026
github-actions Bot added a commit that referenced this pull request May 18, 2026
github-actions Bot added a commit to IndiaAce/sublime-rules that referenced this pull request May 19, 2026
@cameron-dunn-sublime cameron-dunn-sublime removed their request for review May 20, 2026 16:43
Legitimate HubSpot ecosystem senders (andopen.co gifting, Wisetek,
Deloitte immigration, HubSpot QA) all have 'hubspot' in their sender
email. Attackers use unrelated domains or 'hubsp0t' typosquatting.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
github-actions Bot added a commit that referenced this pull request May 29, 2026
github-actions Bot added a commit to IndiaAce/sublime-rules that referenced this pull request May 29, 2026
github-actions Bot added a commit that referenced this pull request May 29, 2026
github-actions Bot added a commit to IndiaAce/sublime-rules that referenced this pull request May 29, 2026
github-actions Bot added a commit that referenced this pull request May 29, 2026
github-actions Bot added a commit that referenced this pull request May 29, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

in-test-rules PR is in our testing suite to collect telemetry

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants