Trend Micro analyzed a targeted attack against a Taiwanese government entity which used a variant of the PlugX RAT that abuses the Dropbox service. This is the first time Dropbox has been used to store C&C settings as part of the targeted attack. The use of Dropbox aids in masking the malicious traffic in the network because this is a legitimate website for storing files and documents. Cybercriminals recognize the business benefits of cloud services and will likely continue to migrate from self-hosted (or compromised) attacks to cloud services.”]

