Skip to content

Create body_spouse_fake_call.yml#4317

Draft
keaton-sublime wants to merge 5 commits intomainfrom
keaton-sublime.fn.fake_call_fake_zoom
Draft

Create body_spouse_fake_call.yml#4317
keaton-sublime wants to merge 5 commits intomainfrom
keaton-sublime.fn.fake_call_fake_zoom

Conversation

@keaton-sublime
Copy link
Copy Markdown
Member

@keaton-sublime keaton-sublime commented Apr 6, 2026

Description

Catches part of the "benign" conversations which eventually involve a fake zoom/google meet link that typically goes on to install RMMs. In our observations, these have typically occurred in the second or third to last reply in a thread.

  • Requesting Live PR on this one pls

Associated samples

Associated hunts

@keaton-sublime keaton-sublime added the in-test-rules PR is in our testing suite to collect telemetry label Apr 6, 2026
github-actions Bot added a commit that referenced this pull request Apr 6, 2026
github-actions Bot added a commit that referenced this pull request Apr 6, 2026
@keaton-sublime
Copy link
Copy Markdown
Member Author

updated multi-hunt

github-actions Bot added a commit to IndiaAce/sublime-rules that referenced this pull request Apr 8, 2026
…sation with spouse mention and video call request
github-actions Bot added a commit that referenced this pull request Apr 9, 2026
…ation with spouse mention and video call request
github-actions Bot added a commit that referenced this pull request Apr 17, 2026
github-actions Bot added a commit that referenced this pull request Apr 17, 2026
…ersation with spouse mention and video call request
@keaton-sublime
Copy link
Copy Markdown
Member Author

Latest hunt and multi-hunt.

@keaton-sublime keaton-sublime marked this pull request as ready for review April 17, 2026 17:50
@keaton-sublime keaton-sublime requested a review from a team April 17, 2026 17:50
@keaton-sublime keaton-sublime requested a review from a team as a code owner April 17, 2026 17:50
@keaton-sublime keaton-sublime added the review-needed Indicates that a PR is waiting for review label Apr 17, 2026
@keaton-sublime
Copy link
Copy Markdown
Member Author

Requesting a Live PR on this one, I have all the hunts and steps saved out as multi-hunts and can walk through the testing.
Marking as review needed/ready for review.

@keaton-sublime keaton-sublime removed the review-needed Indicates that a PR is waiting for review label Apr 20, 2026
@keaton-sublime keaton-sublime marked this pull request as draft April 20, 2026 12:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

in-test-rules PR is in our testing suite to collect telemetry

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant