Netskope Threat Research Labs has observed phishing attacks using decoy PDF files, URL redirection, and Cloud Storage services to infect users and propagate malware. Because many organizations have default “allow” security policies for popular Cloud Storage services and PDF readers to let users take advantage of these useful services, these attacks pass through the corporate network to end users’ machines undetected. Moreover, as users collaborate and share through cloud services, these malicious files posing as PDFs “fan out” to shared users, creating a secondary propagation vector. We are calling this the “CloudPhishing Fan-out Effect.”
In this blog, we will detail the insidious nat