How it works

Attaching a file trips mail filters, so this version links out instead. The email points to "the full brief," "campaign details," or "the contract" on a cloud host such as Dropbox, Google Drive, Discord's CDN, or MediaFire, or on a domain that only resembles the brand's real one. The download is a stealer from the RedLine or Lumma family, packaged as brief.zip, campaign_details.exe, or a padded installer that looks oversized so it appears harmless.

These families exist to collect browser cookies, saved passwords, and the active YouTube and Google session token, then hand them to whoever bought the log. Posing as a familiar software sponsor such as Honey makes "download the brief before our call" feel like an ordinary request.

The tell-tale signals

What to do

A brief is something you read, not a program you run. Ask for it as a PDF or a Google Doc you can preview in the browser without downloading anything. If the link ends in .exe, .scr, .zip, .rar, or .7z, do not open it. Check the sending domain against the brand's real ones, which for Honey are joinhoney.com and paypal.com. If you downloaded and ran the file, act on the risk immediately: from a clean device, change your Google password, revoke every session, and remove any channel access you do not recognize.