heroui logo

Service abuse: Google callback scam

Sublime Rules

View Source
Summary
Detects inbound messages that spoof Google's no-reply notification address by validating the sender and analyzing the message body for callback scam intent. The rule triggers when the email appears to come from no-reply@accounts.google.com and the body text (body.current_thread.text) is analyzed by an NLU classifier (ml.nlu_classifier) returning an intent named "callback_scam" with a confidence level that is not "low" (i.e., medium or high). This indicates a potential callback phishing attempt designed to prompt user action through social engineering and brand spoofing. The detection relies on two methods: sender analysis to verify the purported sender identity and natural language understanding to identify scam-oriented content. It is categorized as medium severity and aligned with attacks that leverage impersonation and spoofing to elicit a response based on a trusted brand.
Categories
  • Other
Data Sources
  • Script
Created: 2026-10-06