Brand-impersonation credential phishing lure

SE_BRAND_CREDENTIAL_PHISH

← All detection heuristics · Social Engineering

high SE_BRAND_CREDENTIAL_PHISH

What it means

Document impersonates a well-known consumer brand and uses account-security language to drive the reader to a credential-harvesting link.

Why it fires

The rule fires when a brand name (Amazon, PayPal, Apple, Microsoft, a bank, etc.) appears together with account-security / verification lure language ("unusual activity", "account on hold", "verify your account", "restore access") AND at least one corroborator: lure text written with homoglyph letter swaps (capital 'I' for lowercase 'l', e.g. "hoId", "unusuaI" — a deliberate keyword-filter evasion), an action link to an abused app-hosting / redirector service (Google Apps Script /macros/.../exec, *.web.app, *.workers.dev, Google Forms), or a call-to-action link whose host does not match the impersonated brand's own domain. Requiring a corroborator keeps legitimate brand notices — which link to the real domain and spell their words normally — from tripping it. Critical when the link points at an abused redirector or two corroborators are present.

Other Social Engineering heuristics

SE_BOOKING_COMPLAINT_PHISH PDF_FAKE_DOCUMENT_COMPONENT_INSTALLER OOXML_QR_CREDENTIAL_PHISH SE_CALLBACK_SCAM_TEMPLATE PDF_BRAND_ACCOUNT_UPDATE_REDIRECT_LURE PDF_IMAGE_REPEATED_DECOY_REDIRECT_LURE PDF_IMAGE_DOCUMENT_REVIEW_HOST_LURE PDF_LOCALIZED_DOWNLOAD_HOSTING_LURE PDF_MINIMAL_VIEW_DOCUMENT_REDIRECT PDF_NESTED_ENCODED_CROSSHOST_REDIRECT PDF_RFP_EXTERNAL_ACTION_LURE PDF_UTILITY_REFUND_OFFDOMAIN_LURE PDF_SPARSE_MOVED_ARTICLE_DOORWAY