
Case study Enterprise
Trusted File Sharing Became a Malware Route
Unit6 observed an actor using an authentic file-sharing service to distribute malware and support phishing with MFA-bypass proxies. The trusted service made the campaign less obvious than a lookalike domain alone.
Impact summary
Unit6 observed an actor using an authentic file-sharing service to distribute malware and support phishing with MFA-bypass proxies. The trusted service made the campaign less obvious than a lookalike domain alone.

01 / Observation
What Unit6 saw
Unit6 observed the actor’s preparation across:
- 01
Use of an authentic file-sharing service to distribute malware
- 02
Spearphishing activity tied to the same targeting effort
- 03
MFA-bypass proxy infrastructure in the attack sequence
02 / Significance
Why it mattered
A real collaboration platform carries the credibility of a service employees may already use.
The actor used the service and related phishing infrastructure. Malware execution and account loss were not confirmed.
03 / Confidence
How Unit6 established confidence
Malware distribution, spearphishing preparation, and MFA-bypass proxy use
The published account omits the service name, links, and infrastructure details that could identify the target.
04 / Recommended response
What the customer could do
The evidence supported a focused defensive response:
- Review and block the malicious shared content and associated delivery paths
- Warn likely recipients and inspect sign-ins for proxy-mediated authentication
- Investigate any downloaded files or new sessions before assuming infection
05 / Outcome not confirmed
Outcome
The trusted delivery path could have increased the chance of malware execution or account takeover.
No completed infection, credential theft, or customer containment was confirmed.



