heroui logo

Link: Gmail confidential mode message with job scam subject

Sublime Rules

View Source
Summary
This rule detects Gmail confidential mode messages that misuse the sender-controlled subject (rendered as the link text) or the sender address to promote job scams or recruitment. It targets inbound emails whose thread contains a link to confidential-mail.google.com with a path starting /msg/. The rule analyzes the link display_text using an NLU classifier to identify job_scam intents with medium or high confidence, or to detect financial cues (e.g., compensation figures like $450K–$900K). It also flags recruitment language in the link text (e.g., terms related to leadership roles, careers, jobs) and recruitment-related patterns in the sender's local-part (e.g., recruit, talent, staffing, executive, career). If any of these conditions are met, the event is marked as a potential BEC/Fraud or Credential Phishing attempt, leveraging content analysis, natural language understanding, sender analysis, and URL analysis as detection methods. This detection focuses on social engineering embedded in credential-related lure within confidential mode mail links, aiming to reduce successful phishing attempts that rely on recruitment rhetoric and deceptive subject/link text.
Categories
  • Web
Data Sources
  • Process
Created: 2026-10-07