logo

Fake Dropbox Phishing Campaign Targets Users, Steals Login Credentials

ID: c90caf06-588d-5c24-b922-db6db0c513ed

STIX ID: report--c90caf06-588d-5c24-b922-db6db0c513ed

Feed Name: GBHackers

Threat Score
70/100

Date Published: 2026-02-03

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

A sophisticated procurement-themed phishing campaign delivers malicious PDFs that leverage AcroForm objects and legitimate Vercel Blob storage to redirect victims to a fake Dropbox login page (tovz.life) that captures credentials and exfiltrates them via a Telegram bot. The report provides IOCs (PDF names and SHA1s, cloud-hosted PDF URL, redirected URL, and Telegram API endpoint), analyzes the evasion techniques, and recommends email filtering for PDFs, MFA enforcement, and user awareness training.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.