Tactic or Technique: Free file host

Phishing attacks often use trusted file-sharing platforms like Google Drive, OneDrive, or Dropbox to deliver malicious content. Instead of attaching malware directly to an email, they send a link to a hosted file that contains a phishing page, ransomware, or another type of malicious payload.
Because these services are widely used and trusted, the links don’t always look suspicious—and many security tools allow them by default. Encrypted connections make it harder to inspect the content, and the familiar branding gives the message an added layer of credibility.
This tactic is effective because it blends in with everyday workflows. A file share link feels normal, especially if it’s framed as a contract, invoice, or shared HR document. That’s why it often gets past both technical defenses and human intuition. Without cloud-aware security controls or strong user training, it’s easy for one click to lead to compromise.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Link: Google Cloud Storage with echo-tail od= tracking token
4h ago
Oct 6th, 2026
Sublime Security
Link: Google Cloud Storage with suspicious URL pattern
4h ago
Oct 6th, 2026
Sublime Security
Link: Google Cloud Storage /index and /unsub link pair
4h ago
Oct 6th, 2026
Sublime Security
Link: Google Cloud Storage with prefixed base64 dash-record fragment
5h ago
Oct 6th, 2026
Sublime Security
Link: Google Cloud Storage with zipper-interleaved tracking token
5h ago
Oct 6th, 2026
Sublime Security
Link: Google Cloud Storage with suffixed unsubscribe bucket
5h ago
Oct 6th, 2026
Sublime Security
Link: Google Cloud Storage with case-striped tracking token in fragment
5h ago
Oct 6th, 2026
Sublime Security
Link: Google Cloud Storage with base64 go/sub-ID fragment
5h ago
Oct 6th, 2026
Sublime Security
Link: Google Cloud Storage with short-path link delivery
5h ago
Oct 6th, 2026
Sublime Security
Attachment: Excel file with hyperlinks to suspicious domains
6h ago
Oct 6th, 2026
Sublime Security
Credential phishing: Hyper-linked image leading to free file host
7d ago
Sep 29th, 2026
Sublime Security
Link: Suspicious SharePoint document name
8d ago
Sep 28th, 2026
Sublime Security
Attachment: ICS calendar invite with bid/RFP lure and suspicious link
8d ago
Sep 28th, 2026
Sublime Security
Attachment: ICS file with credential theft indicators
8d ago
Sep 28th, 2026
Sublime Security
Attachment: ICS voicemail lure with suspicious link
8d ago
Sep 28th, 2026
Sublime Security
Link: Google Cloud Storage short filename pattern
8d ago
Sep 28th, 2026
Sublime Security
Attachment: ICS calendar with suspicious link Leading to minimal JS landing page
8d ago
Sep 28th, 2026
Sublime Security
Link: Google Calendar invite linking to an open redirect from an untrusted freemail sender
8d ago
Sep 28th, 2026
Sublime Security
Attachment: Calendar invite with suspicious link leading to an open redirect
8d ago
Sep 28th, 2026
Sublime Security
Brand impersonation: Fake Fax
11d ago
Sep 25th, 2026
Sublime Security