That Dropbox link in your inbox could be a scam (2024)

That Dropbox link in your inbox could be a scam (1)

Cybercriminals are abusing legitimate cloud services to make sure their malicious files make it to people’s inboxes, new research from Check Point have said.

Dubbingthe practice Business Email Compromise (BEC) 3.0, the researchers said email service providers had gotten a lot better at spotting and filtering malicious emails.

So in order to work around this, hackers have started using legitimate cloud services, especially those that offer free trial accounts. They would create a free account on a platform such as Dropbox, and use that service to send an email to their victim, carrying a malicious link. Given that the email would be coming from a trusted source and a known domain, email security services can do nothing but let the message reach the inbox.

That Dropbox link in your inbox could be a scam (2)

<a href="https://www.perimeter81.com/lp/malware-protection-techradar?a_aid=2380&utm_term=secure_internet_access&utm_source=techradar&utm_medium=affiliate&utm_campaign=deal_block" data-link-merchant="perimeter81.com"" target="_blank">Protecting your business from the biggest threats online
Perimeter 81's Malware Protection intercepts threats at the delivery stage to prevent known malware, polymorphic attacks, zero-day exploits, and more. Let your people use the web freely without risking data and network security.

Preferred partner (<a href="https://www.techradar.com/news/content-funding-on-techradar" data-link-merchant="techradar.com"" data-link-merchant="perimeter81.com"" target="_self">What does this mean?)

Abusing filesharing services

In an example, Check Point said the attackers would create a malicious file and host it on Dropbox. They would then use the platform’s built-in sharing feature to email the link to the malicious file to their victims. As there’s nothing malicious about the email itself, the message would make it into the victim’s inbox.

If the victim opens the file, they would be prompted with a login form asking for their email address and password. In this, first step, the victims would already be giving their Dropbox credentials to the attackers. In the next step, the attackers would redirect the victim to a malicious URL, where they’d be asked for their OneDrive login credentials, as well.

Read more

> Dropbox wants to cut down on the number of apps you use at work> What is phishing and how dangerous is it?> These are the best firewalls right now

“So the hackers, using a legitimate site, have created two potential breaches: They will get your credentials and then potentially induce you to click on a malicious URL,” the researchers explained. “That’s because the URL itself is legitimate. It’s the content on the website that’s problematic. You’ll see the hackers mocked up a page that looks like OneDrive. When clicking on the link, users are given a malicious download. “

As usual, the best way to protect against email-borne attacks is to use common sense and not click on unexpected and suspicious links and email attachments.

Are you a pro? Subscribe to our newsletter

Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

  • Here are the best ID theft protection services around

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

More about security

Crypto miner arrested for skipping on millions in cloud server billsA sneaky new steganography malware is exploiting Microsoft Word — hundreds of firms around the world hit by attack

Latest

The AOKZOE A2 Ultra could be Intel's chance for a PC gaming handheld redemption
See more latest►

Most Popular
Google Chrome will soon let you talk to Gemini right in the address bar
The Microsoft Store gets a turbo boost in new update, promising speedier and sleeker performance
Arrowhead says it will be making changes to Helldivers 2's 'ridiculous' fire damage
Samsung's stunning Frame TV is my dream display and it's now cheaper than ever
Nvidia's new A400 and A1000 GPUs look to bring generative AI even to your office workstation
Surfshark drops new Apple TV VPN app
The latest macOS Ventura update has left owners of old Macs stranded in a sea of problems, raising a chorus of complaints
Bad bots made up almost a third of all internet traffic last year
PC Gaming Show returns in June, featuring "over 50 games" and world premiere announcements
A Nintendo Indie World Showcase is confirmed for tomorrow, here’s how and when to watch
Sony’s new 16-25mm is its lightest and smallest ever ultra-wide f/2.8 zoom lens, but it comes with a catch
That Dropbox link in your inbox could be a scam (2024)
Top Articles
Latest Posts
Article information

Author: Carmelo Roob

Last Updated:

Views: 5670

Rating: 4.4 / 5 (45 voted)

Reviews: 84% of readers found this page helpful

Author information

Name: Carmelo Roob

Birthday: 1995-01-09

Address: Apt. 915 481 Sipes Cliff, New Gonzalobury, CO 80176

Phone: +6773780339780

Job: Sales Executive

Hobby: Gaming, Jogging, Rugby, Video gaming, Handball, Ice skating, Web surfing

Introduction: My name is Carmelo Roob, I am a modern, handsome, delightful, comfortable, attractive, vast, good person who loves writing and wants to share my knowledge and understanding with you.