logo

Dropbox Abused in New Phishing, Malspam Scam to Steal SaaS Logins

ID: 2f1959a1-9b9e-5e79-ad88-6b78689affa3

STIX ID: report--2f1959a1-9b9e-5e79-ad88-6b78689affa3

Feed Name: HackRead

Threat Score
70/100

Date Published: 2024-03-11

Date Updated: 2026-04-22

Author: Waqas

...
...

Darktrace researchers observed a Dropbox-themed phishing and malspam campaign that sends emails from seemingly legitimate Dropbox addresses containing links to PDFs; those PDFs host links to a malicious domain (mmv-securitytop) that redirects users to a fake Microsoft 365 login page to harvest SaaS credentials. Attackers were observed bypassing MFA using valid tokens, creating mailbox rules to hide malicious messages, and using VPN services to obscure their locations, resulting in suspicious logins and potential SaaS account compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.