Beware of Fake Dropbox Phishing Attack that Harvest Login Credentials
ID: f4f19663-b5d8-5907-bda9-0123050c2fcd
STIX ID: report--f4f19663-b5d8-5907-bda9-0123050c2fcd
Feed Name: cybersecurityNews.com
Cybercriminals are conducting a multi-stage Dropbox-themed phishing campaign that uses legitimate-looking procurement emails with benign PDF attachments; those PDFs link to cloud-hosted staging documents (Vercel Blob) which then redirect victims to a fake Dropbox login. The staged PDFs use FlateDecode and AcroForm techniques to hide clickable elements and evade scanners, while client-side JavaScript captures credentials, gathers IP/geo information, and forwards the data to attackers via a Telegram bot, then simulates a failed login to avoid detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
