logo

New Password-Stealing Phishing Campaign Targets Corporate Dropbox Credentials

ID: e6909e1a-5fdc-551f-b499-90137004850a

STIX ID: report--e6909e1a-5fdc-551f-b499-90137004850a

Feed Name: Infosecurity Magazine (News)

Threat Score
65/100

Date Published: 2026-02-03

Date Updated: 2026-04-22

...
...

Forcepoint X‑Labs warns of a multi-stage phishing campaign targeting corporate users: short procurement-style emails prompt recipients to open PDFs containing AcroForm links that lead to a fake Dropbox login hosted on legitimate cloud infrastructure. The attackers harvest credentials submitted to the spoofed page and forward them to a Telegram channel for account takeover and potential follow-on attacks, using techniques designed to evade email authentication and automated scanning.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.