heroui logo

Service abuse: Apple callback scam

Sublime Rules

View Source
Summary
The rule detects inbound email messages that purport to come from Apple's noreply address but show spoofing indicators in header data and content. It requires: 1) the sender.email equals noreply@email.apple.com; 2) any reply-to header whose root domain is not apple.com; 3) a Natural Language Understanding (NLU) classifier applied to the message body that identifies intent labeled 'callback_scam' with a confidence that is not 'low' (i.e., medium or high). When all conditions are met, the rule triggers for medium severity, classifying this as a Callback Phishing attempt involving social engineering and potential out-of-band pivot. This approach combines sender and header analysis with NLP to detect nuanced phishing attempts that rely on legitimate branding to provoke a callback.
Categories
  • Endpoint
  • Network
Data Sources
  • Network Traffic
Created: 2026-09-30