Threat actors are running malware-free phishing campaigns designed to steal cloud-storage credentials by pushing victims through believable, multi-step lures. One observed operation sends corporate users emails requesting review of a fake “request order” via a linked PDF; the PDF then directs recipients to a convincing fake Dropbox login page that captures credentials and location data while returning an “incorrect username/password” error to reduce suspicion and encourage retries.
Separately, a large-scale cloud storage subscription/payment scam has been flooding inboxes worldwide with repeated “renewal” and “payment declined” messages claiming accounts will be blocked or files deleted unless immediate action is taken. The campaign uses many randomized sender domains and high-urgency, frequently personalized subject lines to drive clicks, indicating broad, high-volume social engineering aimed at harvesting account access or payment details rather than delivering traditional malware.

Get the infrastructure and lures behind it.
3 events from the most recent confirmed update back to the earliest known activity.
Forcepoint published research on a malware-free phishing campaign stealing corporate Dropbox credentials through fake 'request order' PDF lures. The multi-stage attack used a cloud-hosted blurred document and a convincing fake Dropbox login page, while also sending victim system and location data to an attacker-controlled Telegram bot.
Researchers reported that the cloud storage scam used static HTML redirectors hosted on storage.googleapis.com to send victims to scam domains. The landing pages impersonated cloud service portals, showed fake storage warnings, and funneled users toward affiliate offers and credit-card collection pages.
A large-scale phishing campaign began targeting users with repeated fake cloud storage renewal and payment-failure emails claiming accounts would be blocked or files deleted. The messages used personalized subject lines and urgency to drive victims into the scam flow.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
4 references tracked. Mallory keeps watching after this page renders.
forcepoint.com
Open sourcedarkreading.com
Open sourcecsoonline.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.