Tactic or Technique: Free file host

Phishing attacks often use trusted file-sharing platforms like Google Drive, OneDrive, or Dropbox to deliver malicious content. Instead of attaching malware directly to an email, they send a link to a hosted file that contains a phishing page, ransomware, or another type of malicious payload.
Because these services are widely used and trusted, the links don’t always look suspicious—and many security tools allow them by default. Encrypted connections make it harder to inspect the content, and the familiar branding gives the message an added layer of credibility.
This tactic is effective because it blends in with everyday workflows. A file share link feels normal, especially if it’s framed as a contract, invoice, or shared HR document. That’s why it often gets past both technical defenses and human intuition. Without cloud-aware security controls or strong user training, it’s easy for one click to lead to compromise.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Link: Mismatched free file host links with document lure
2d ago
Aug 5th, 2026
Sublime Security
Low reputation link to auto-downloaded HTML file with smuggling indicators
9d ago
Jul 29th, 2026
Sublime Security
Attachment: EML with link to credential phishing page
11d ago
Jul 27th, 2026
Sublime Security
DocuSign impersonation via CloudHQ links
11d ago
Jul 27th, 2026
Sublime Security
Service abuse: FileMail callback scam
14d ago
Jul 24th, 2026
Sublime Security
Attachment: ICS file with AWS Lambda URL
22d ago
Jul 16th, 2026
Sublime Security
Link: Multistage landing - Trello board abuse
22d ago
Jul 16th, 2026
Sublime Security
Attachment: Single-page PDF with S3-hosted HTML link
22d ago
Jul 16th, 2026
Sublime Security
Link: Free file host link with 'Important Viewing Note' lure
23d ago
Jul 15th, 2026
Sublime Security
Zoom Events newsletter abuse
30d ago
Jul 8th, 2026
Sublime Security
Open redirect: JustPaste.it
1mo ago
Jul 2nd, 2026
Sublime Security
Attachment: Romance scam with image lure and advance-fee or suspicious link indicators
1mo ago
Jul 1st, 2026
Sublime Security
Link: Google Cloud Storage link with index.php in URL
1mo ago
Jun 30th, 2026
Sublime Security
Link: Google Cloud Storage redirect to external domain
1mo ago
Jun 30th, 2026
Sublime Security
Link: Google Cloud Storage with short-path link delivery
1mo ago
Jun 30th, 2026
Sublime Security
Link: Google Cloud Storage link with redirect.html in URL
1mo ago
Jun 30th, 2026
Sublime Security
Link: Google Cloud Storage hosted credential harvesting page
1mo ago
Jun 30th, 2026
Sublime Security
Cloud storage impersonation with credential theft indicators
1mo ago
Jun 30th, 2026
Sublime Security
Link: Free file host links from suspicious support sender with credential theft language
1mo ago
Jun 25th, 2026
Sublime Security
Service abuse: DocSend share from an unsolicited reply-to address
1mo ago
Jun 18th, 2026
Sublime Security