Tactic or Technique: Free file host

Phishing attacks often use trusted file-sharing platforms like Google Drive, OneDrive, or Dropbox to deliver malicious content. Instead of attaching malware directly to an email, they send a link to a hosted file that contains a phishing page, ransomware, or another type of malicious payload.
Because these services are widely used and trusted, the links don’t always look suspicious—and many security tools allow them by default. Encrypted connections make it harder to inspect the content, and the familiar branding gives the message an added layer of credibility.
This tactic is effective because it blends in with everyday workflows. A file share link feels normal, especially if it’s framed as a contract, invoice, or shared HR document. That’s why it often gets past both technical defenses and human intuition. Without cloud-aware security controls or strong user training, it’s easy for one click to lead to compromise.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Brand impersonation: Fake Fax
2d ago
Jan 21st, 2026
Sublime Security
/feeds/core/detection-rules/brand-impersonation-fake-fax-2a96b90a
Link: Secure SharePoint file share from new or unusual sender
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/link-secure-sharepoint-file-share-from-new-or-unusual-sender-74ed3020
Service abuse: FlipHTML5 with attachment deception and credential theft language
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/service-abuse-fliphtml5-with-attachment-deception-and-credential-theft-language-02464799
Zoom Events newsletter abuse
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/zoom-events-newsletter-abuse-c8fce846
Spam: Campaign with excessive space/char obfuscation and free file hosted link
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/spam-campaign-with-excessive-spacechar-obfuscation-and-free-file-hosted-link-122bc0ca
Suspicious Links to Cloudflare R2 and Edge Services
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/suspicious-links-to-cloudflare-r2-and-edge-services-5dd3e5c8
Service abuse: DocuSign share from an unsolicited reply-to address
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/service-abuse-docusign-share-from-an-unsolicited-reply-to-address-2f12d616
Deceptive Dropbox mention
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/deceptive-dropbox-mention-58a107bc
Low reputation link to auto-downloaded HTML file with smuggling indicators
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/low-reputation-link-to-auto-downloaded-html-file-with-smuggling-indicators-339676c6
Link: Direct link to riddle.com hosted showcase
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/link-direct-link-to-riddlecom-hosted-showcase-cca7d2f5
Service abuse: DocSend share from newly registered domain
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/service-abuse-docsend-share-from-newly-registered-domain-3bc152f2
Service abuse: SurveyMonkey survey from newly registered domain
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/service-abuse-surveymonkey-survey-from-newly-registered-domain-50a85fa7
Fake scan-to-email message
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/fake-scan-to-email-message-78851fbe
Issuu document with suspicious embedded link
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/issuu-document-with-suspicious-embedded-link-0d73f43d
Link: Adobe share with suspicious indicators
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/link-adobe-share-with-suspicious-indicators-b33cae80
Link: Adobe share from unsolicited sender
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/link-adobe-share-from-unsolicited-sender-8e29ab33
Google share notification with suspicious comments
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/google-share-notification-with-suspicious-comments-c69c9924
Link: IPFS
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/link-ipfs-19fa6442
Link: Jensi file preview link from unsolicited sender
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/link-jensi-file-preview-link-from-unsolicited-sender-122b39f3
Brand impersonation: Microsoft with low reputation links
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/brand-impersonation-microsoft-with-low-reputation-links-b59201b6