Skip to case study
All case studies

Case study Enterprise

Trusted File Sharing Became a Malware Route

Unit6 observed an actor using an authentic file-sharing service to distribute malware and support phishing with MFA-bypass proxies. The trusted service made the campaign less obvious than a lookalike domain alone.

ThreatAn actor incorporated a legitimate file-sharing service into a targeted campaign
What Unit6 sawMalware and MFA-bypass phishing via a real service
What was at riskTrusted service abuse surfaced

Impact summary

Unit6 observed an actor using an authentic file-sharing service to distribute malware and support phishing with MFA-bypass proxies. The trusted service made the campaign less obvious than a lookalike domain alone.

Illustrative close-up of a blank shared-file artifact with a restrained warning reflection

01 / Observation

What Unit6 saw

Unit6 observed the actor’s preparation across:

  1. 01

    Use of an authentic file-sharing service to distribute malware

  2. 02

    Spearphishing activity tied to the same targeting effort

  3. 03

    MFA-bypass proxy infrastructure in the attack sequence

02 / Significance

Why it mattered

A real collaboration platform carries the credibility of a service employees may already use.

The actor used the service and related phishing infrastructure. Malware execution and account loss were not confirmed.

03 / Confidence

How Unit6 established confidence

Malware distribution, spearphishing preparation, and MFA-bypass proxy use

The published account omits the service name, links, and infrastructure details that could identify the target.

04 / Recommended response

What the customer could do

The evidence supported a focused defensive response:

  • Review and block the malicious shared content and associated delivery paths
  • Warn likely recipients and inspect sign-ins for proxy-mediated authentication
  • Investigate any downloaded files or new sessions before assuming infection

05 / Outcome not confirmed

Outcome

The trusted delivery path could have increased the chance of malware execution or account takeover.

No completed infection, credential theft, or customer containment was confirmed.

See what happens when you know first.

You’ve seen their hands.
Now let’s look at yours.

Book a demo