logo

Beware of Fake Dropbox Phishing Attack that Harvest Login Credentials

ID: f4f19663-b5d8-5907-bda9-0123050c2fcd

STIX ID: report--f4f19663-b5d8-5907-bda9-0123050c2fcd

Feed Name: cybersecurityNews.com

Threat Score
60/100

Date Published: 2026-02-03

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

Cybercriminals are conducting a multi-stage Dropbox-themed phishing campaign that uses legitimate-looking procurement emails with benign PDF attachments; those PDFs link to cloud-hosted staging documents (Vercel Blob) which then redirect victims to a fake Dropbox login. The staged PDFs use FlateDecode and AcroForm techniques to hide clickable elements and evade scanners, while client-side JavaScript captures credentials, gathers IP/geo information, and forwards the data to attackers via a Telegram bot, then simulates a failed login to avoid detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.