logo

Attackers Harvest Dropbox Logins Via Fake PDF Lures

ID: f176b6f7-d383-5cef-a200-7101dc9ef1c7

STIX ID: report--f176b6f7-d383-5cef-a200-7101dc9ef1c7

Feed Name: Dark Reading

Threat Score
60/100

Date Published: 2026-02-02

Date Updated: 2026-04-21

Author: Alexander Culafi

...
...

Forcepoint reported an active phishing campaign that sends a PDF lure leading to a blurred invoice hosted on legitimate cloud infrastructure; that document contains a link to a convincing Dropbox credential-phishing page which captures login details and system/location data (sent to a Telegram bot). The attack uses spoofed or compromised internal email addresses and legitimate hosting to pass SPF/DKIM/DMARC and evade detection, contains no malware, and Forcepoint published IOCs and mitigation advice.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.