Skip to content

Create body_spouse_fake_call.yml#4317

Draft
keaton-sublime wants to merge 4 commits intomainfrom
keaton-sublime.fn.fake_call_fake_zoom
Draft

Create body_spouse_fake_call.yml#4317
keaton-sublime wants to merge 4 commits intomainfrom
keaton-sublime.fn.fake_call_fake_zoom

Conversation

@keaton-sublime
Copy link
Copy Markdown
Member

@keaton-sublime keaton-sublime commented Apr 6, 2026

Description

Catches part of the "benign" conversations which eventually involve a fake zoom/google meet link that typically goes on to install RMMs. In our observations, these have typically occurred in the second or third to last reply in a thread.

Associated samples

Associated hunts

@keaton-sublime keaton-sublime added the in-test-rules PR is in our testing suite to collect telemetry label Apr 6, 2026
github-actions bot added a commit that referenced this pull request Apr 6, 2026
github-actions bot added a commit that referenced this pull request Apr 6, 2026
@keaton-sublime
Copy link
Copy Markdown
Member Author

updated multi-hunt

github-actions bot added a commit to IndiaAce/sublime-rules that referenced this pull request Apr 8, 2026
…sation with spouse mention and video call request
github-actions bot added a commit that referenced this pull request Apr 9, 2026
…ation with spouse mention and video call request
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

in-test-rules PR is in our testing suite to collect telemetry

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant