09/05/2024
In the last couple of weeks, I have seen a new phishing campaign doing the rounds.
This starts with someone you know whose mailbox/Dropbox account has been compromised. You are sent a file via Dropbox by the threat actor. The share email sends you to the legitimate Dropbox website, but the "PDF" links you to a phishing website.
As the email comes from a legitimate filehost and the contents of the share cannot be scanned by your email vendor, it's down to you to avoid falling foul of it.
Those who fall victim to this, will risk their email/Dropbox account being accessed and used to spam friends, colleagues and clients (all rather embarrassing!).