heroui logo

Brand impersonation: Kroger

Sublime Rules

View Source
Summary
Detects inbound emails that impersonate Kroger by spoofed display name or local-part and reference loyalty-program terms in the message body or in a rendered image via OCR. The rule first flags messages where the sender display name or local-part resembles 'Kroger', then requires Kroger-related language (e.g., 'boost membership', 'points balance', 'loyalty program', 'special member offer') or a 'shopping cart reward' pattern found in the content or OCR-extracted text. Legitimate messages from verified Kroger domains or high-trust senders that pass DMARC, as well as newsletters/digests, are excluded to reduce false positives. Additional exclusions apply for messages from known Kroger domains or other high-trust domains with DMARC pass. Attack types include Credential Phishing and BEC/Fraud. Tactics include Brand impersonation, social engineering, and image-based content. Detection methods cover sender analysis, content analysis, OCR, natural language understanding, and header analysis. The rule relies on a beta OCR feature for image content and includes exclusions to minimize false positives from legitimate communications and high-trust sources.
Categories
  • Web
  • Application
  • Other
Data Sources
  • Process
  • Image
Created: 2026-09-15