Dropbox Watchdog

Search issues

Search the Dropbox Watchdog archive

All issues

Sync-folder exfiltration: malware that hides command-and-control inside Dropbox folders

2013–2024

MediumStatus: OngoingProduct: Core syncYear: 2021

The DropSmack proof-of-concept warned that synced Dropbox folders could be a covert C2 and exfiltration channel; multiple real malware families — including BoxCaon, Crutch and tooling used by Kimsuky — went on to abuse Dropbox folders and the Dropbox API exactly that way.

What happened

The 2013 'DropSmack' research showed in principle that an always-on Dropbox sync folder is an ideal covert channel: drop a command file into a shared folder and a compromised endpoint will receive it; write stolen data into the folder and it syncs out — all over encrypted, firewall-friendly traffic. In the years since, that concept has been realized by real intrusion sets. Beyond Worok's DropBoxControl, security vendors have documented malware families such as BoxCaon and ESET's 'Crutch' (linked to the Turla group) staging data in Dropbox, and North Korea-linked Kimsuky operations using PowerShell that pulls follow-on scripts from Dropbox as a C2 channel.

In each case the attraction is operational: Dropbox traffic is ubiquitous and trusted, so blending C2 and exfiltration into it defeats perimeter and reputation defenses that would flag an unknown server. The recurring use across unrelated actors marks Dropbox-as-C2 as an established technique rather than a one-off.

Impact

This recurring abuse keeps Dropbox among the legitimate services repeatedly co-opted for espionage-grade command-and-control and data theft, forcing defenders to treat sanctioned cloud-sync traffic as a monitoring problem rather than something safe to ignore. It is the operational legacy of the structural risk DropSmack first flagged: the same convenience that makes Dropbox useful makes it a stealthy tunnel out of an organization.

Dropbox's Response / Official Position

Dropbox disables abusive accounts and provides an abuse-reporting channel, and has long pointed enterprises toward administrative controls and visibility in its business tier to manage unsanctioned use; the specific malware families were identified by ESET, Avast and other researchers rather than by Dropbox disclosures.

Sources

Related guides

Spot an error, or have a source to add?
Report an error / suggest update

Related issues

9 sources
HighApproximately 5,000 accounts; files accessed in fewer than a third (about 1,500 by 9to5Mac's arithmetic)

The 2026 Lenovo ID sign-in flaw: ~5,000 Dropbox accounts entered without a Dropbox password

A flaw in how Lenovo verified account-holder email addresses let an attacker register a Lenovo ID on a victim's email, and Dropbox's Lenovo ID sign-in link then trusted that identity without ever asking for a Dropbox password — reaching roughly 5,000 accounts.

Security Incidents & Data BreachesCurrent / Ongoing Issues (2024–2026)
Read documentation

Across multiple years, attackers have built convincing fake Dropbox login pages — reached via PDF lures and redirect chains through trusted cloud storage — to harvest victims' real business email and Dropbox credentials.

Security Incidents & Data BreachesAccount Lockouts & Support Failures
Read documentation

ConsentFix, an OAuth-consent phishing technique first documented by Push Security in December 2025 and reported on independently through mid-2026, delivers its Microsoft 365 lures through trusted file-hosting platforms — reporting names both Dropbox and DocSend (a Dropbox company) as hosts for the password-protected files attackers use to get past mail filters.

Security Incidents & Data BreachesCurrent / Ongoing Issues (2024–2026)
Read documentation

Because Dash can be downloaded and set up with 'no sales or IT required,' an individual employee can connect and index an organization's apps and browser history without administrator oversight — recreating the shadow-IT data-governance risk that earlier consumer Dropbox use posed to enterprises.

Privacy & Encryption ConcernsCurrent / Ongoing Issues (2024–2026)Account Lockouts & Support Failures
Read documentation