Fake Dropbox Phishing Campaign Targets Users, Steals Login Credentials
ID: c90caf06-588d-5c24-b922-db6db0c513ed
STIX ID: report--c90caf06-588d-5c24-b922-db6db0c513ed
Feed Name: GBHackers
A sophisticated procurement-themed phishing campaign delivers malicious PDFs that leverage AcroForm objects and legitimate Vercel Blob storage to redirect victims to a fake Dropbox login page (tovz.life) that captures credentials and exfiltrates them via a Telegram bot. The report provides IOCs (PDF names and SHA1s, cloud-hosted PDF URL, redirected URL, and Telegram API endpoint), analyzes the evasion techniques, and recommends email filtering for PDFs, MFA enforcement, and user awareness training.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
