Dropbox Abused in New Phishing, Malspam Scam to Steal SaaS Logins
ID: 2f1959a1-9b9e-5e79-ad88-6b78689affa3
STIX ID: report--2f1959a1-9b9e-5e79-ad88-6b78689affa3
Feed Name: HackRead
Darktrace researchers observed a Dropbox-themed phishing and malspam campaign that sends emails from seemingly legitimate Dropbox addresses containing links to PDFs; those PDFs host links to a malicious domain (mmv-securitytop) that redirects users to a fake Microsoft 365 login page to harvest SaaS credentials. Attackers were observed bypassing MFA using valid tokens, creating mailbox rules to hide malicious messages, and using VPN services to obscure their locations, resulting in suspicious logins and potential SaaS account compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
