Dropbox Watchdog

Search issues

Search the Dropbox Watchdog archive

All issues

Worok's DropBoxControl: malware that used a Dropbox account as its command-and-control

November 2022

MediumStatus: HistoricalProduct: Dropbox APIYear: 2022

ESET and Avast documented the Worok espionage group's 'DropBoxControl' backdoor, which abused the Dropbox API as its entire command-and-control channel — reading commands from, and uploading stolen data to, ordinary files in a Dropbox account.

What happened

In 2022 ESET uncovered attacks by an espionage group it named Worok against organizations across Asia and Africa, and Avast extended the analysis, detailing the group's tooling. The final-stage implant, DropBoxControl, used a threat-actor-controlled Dropbox account as its command-and-control server: the malware periodically polled specific Dropbox folders for request files, executed the commands they contained, and uploaded the results back as files. Stolen data was smuggled out hidden inside PNG images via a loader chain (CLRLoader to PNGLoader to DropBoxControl), with initial access tied to ProxyShell Exchange vulnerabilities.

Because the traffic was just normal Dropbox API calls over HTTPS, the C2 blended into legitimate cloud activity that most networks already permit — the same property that made earlier 'DropSmack' research dangerous, now operationalized by a real intrusion set.

Impact

DropBoxControl is a documented case of attackers turning Dropbox's trusted, ubiquitous API into covert C2 infrastructure, making malicious traffic extremely hard to distinguish from sanctioned cloud use. It sits among a recurring pattern of malware families (including BoxCaon, Crutch and tools used by Kimsuky) that lean on Dropbox for command relay and exfiltration, and it pressures defenders to monitor API/token abuse rather than just block 'bad' domains.

Dropbox's Response / Official Position

Dropbox routinely disables accounts found to be hosting malware or used for command-and-control when abuse is reported, and provides an abuse-reporting channel; the discovery and naming of Worok/DropBoxControl came from ESET and Avast rather than from a Dropbox disclosure.

Sources

Related guides

Spot an error, or have a source to add?
Report an error / suggest update

Related issues

9 sources
HighApproximately 5,000 accounts; files accessed in fewer than a third (about 1,500 by 9to5Mac's arithmetic)

The 2026 Lenovo ID sign-in flaw: ~5,000 Dropbox accounts entered without a Dropbox password

A flaw in how Lenovo verified account-holder email addresses let an attacker register a Lenovo ID on a victim's email, and Dropbox's Lenovo ID sign-in link then trusted that identity without ever asking for a Dropbox password — reaching roughly 5,000 accounts.

Security Incidents & Data BreachesCurrent / Ongoing Issues (2024–2026)
Read documentation

Across multiple years, attackers have built convincing fake Dropbox login pages — reached via PDF lures and redirect chains through trusted cloud storage — to harvest victims' real business email and Dropbox credentials.

Security Incidents & Data BreachesAccount Lockouts & Support Failures
Read documentation

ConsentFix, an OAuth-consent phishing technique first documented by Push Security in December 2025 and reported on independently through mid-2026, delivers its Microsoft 365 lures through trusted file-hosting platforms — reporting names both Dropbox and DocSend (a Dropbox company) as hosts for the password-protected files attackers use to get past mail filters.

Security Incidents & Data BreachesCurrent / Ongoing Issues (2024–2026)
Read documentation

Because Dash can be downloaded and set up with 'no sales or IT required,' an individual employee can connect and index an organization's apps and browser history without administrator oversight — recreating the shadow-IT data-governance risk that earlier consumer Dropbox use posed to enterprises.

Privacy & Encryption ConcernsCurrent / Ongoing Issues (2024–2026)Account Lockouts & Support Failures
Read documentation