Tactic or Technique: Free file host

Phishing attacks often use trusted file-sharing platforms like Google Drive, OneDrive, or Dropbox to deliver malicious content. Instead of attaching malware directly to an email, they send a link to a hosted file that contains a phishing page, ransomware, or another type of malicious payload.
Because these services are widely used and trusted, the links don’t always look suspicious—and many security tools allow them by default. Encrypted connections make it harder to inspect the content, and the familiar branding gives the message an added layer of credibility.
This tactic is effective because it blends in with everyday workflows. A file share link feels normal, especially if it’s framed as a contract, invoice, or shared HR document. That’s why it often gets past both technical defenses and human intuition. Without cloud-aware security controls or strong user training, it’s easy for one click to lead to compromise.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Link: Figma design deck with credential theft language
13h ago
Mar 4th, 2026
Sublime Security
/feeds/core/detection-rules/link-figma-design-deck-with-credential-theft-language-87601924
Service abuse: DocSend share from an unsolicited reply-to address
18h ago
Mar 4th, 2026
Sublime Security
/feeds/core/detection-rules/service-abuse-docsend-share-from-an-unsolicited-reply-to-address-b377e64c
Link: SharePoint OneNote or PDF link with self sender behavior
6d ago
Feb 27th, 2026
Sublime Security
/feeds/core/detection-rules/link-sharepoint-onenote-or-pdf-link-with-self-sender-behavior-588e7203
Link: Multistage landing - ClickUp abuse
6d ago
Feb 27th, 2026
Sublime Security
/feeds/core/detection-rules/link-multistage-landing-clickup-abuse-78a5d035
Attachment: PDF with multistage landing - ClickUp abuse
6d ago
Feb 27th, 2026
Sublime Security
/feeds/core/detection-rules/attachment-pdf-with-multistage-landing-clickup-abuse-0dc40316
Link: URL redirecting to blob URL
9d ago
Feb 24th, 2026
Sublime Security
/feeds/core/detection-rules/link-url-redirecting-to-blob-url-1677135b
Link: Free file hosting with undisclosed recipients
10d ago
Feb 23rd, 2026
Sublime Security
/feeds/core/detection-rules/link-free-file-hosting-with-undisclosed-recipients-b6281306
Cloud storage impersonation with credential theft indicators
13d ago
Feb 20th, 2026
Sublime Security
/feeds/core/detection-rules/cloud-storage-impersonation-with-credential-theft-indicators-4c20f72c
File sharing link with a suspicious subject
16d ago
Feb 17th, 2026
Sublime Security
/feeds/core/detection-rules/file-sharing-link-with-a-suspicious-subject-a306e2a6
Link: Suspicious SharePoint document name
20d ago
Feb 13th, 2026
Sublime Security
/feeds/core/detection-rules/link-suspicious-sharepoint-document-name-f95fee6e
File sharing link from suspicious sender domain
20d ago
Feb 13th, 2026
Sublime Security
/feeds/core/detection-rules/file-sharing-link-from-suspicious-sender-domain-95f20354
Brand impersonation: Fake Fax
28d ago
Feb 5th, 2026
Sublime Security
/feeds/core/detection-rules/brand-impersonation-fake-fax-2a96b90a
Link: Jensi file preview link from unsolicited sender
1mo ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/link-jensi-file-preview-link-from-unsolicited-sender-122b39f3
Brand impersonation: Microsoft with low reputation links
1mo ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/brand-impersonation-microsoft-with-low-reputation-links-b59201b6
Link: Multistage landing - Scribd document
1mo ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/link-multistage-landing-scribd-document-afa9807d
Link: Direct link to riddle.com hosted showcase
1mo ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/link-direct-link-to-riddlecom-hosted-showcase-cca7d2f5
Spam: Campaign with excessive space/char obfuscation and free file hosted link
1mo ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/spam-campaign-with-excessive-spacechar-obfuscation-and-free-file-hosted-link-122bc0ca
Zoom Events newsletter abuse
1mo ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/zoom-events-newsletter-abuse-c8fce846
Link: Secure SharePoint file share from new or unusual sender
1mo ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/link-secure-sharepoint-file-share-from-new-or-unusual-sender-74ed3020
Suspicious Links to Cloudflare R2 and Edge Services
1mo ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/suspicious-links-to-cloudflare-r2-and-edge-services-5dd3e5c8