How it works
Attaching a file trips mail filters, so this version links out instead. The email points to "the full brief," "campaign details," or "the contract" on a cloud host such as Dropbox, Google Drive, Discord's CDN, or MediaFire, or on a domain that only resembles the brand's real one. The download is a stealer from the RedLine or Lumma family, packaged as brief.zip, campaign_details.exe, or a padded installer that looks oversized so it appears harmless.
These families exist to collect browser cookies, saved passwords, and the active YouTube and Google session token, then hand them to whoever bought the log. Posing as a familiar software sponsor such as Honey makes "download the brief before our call" feel like an ordinary request.
The tell-tale signals
- The brief is a download link rather than a document you can read in place
- The download is an .exe, .scr, or an archive
- The link points to a file host, or to a domain that only resembles the brand
- A URL shortener hides where the link actually goes
- Framing like "review this before our call"
What to do
A brief is something you read, not a program you run. Ask for it as a PDF or a Google Doc you can preview in the browser without downloading anything. If the link ends in .exe, .scr, .zip, .rar, or .7z, do not open it. Check the sending domain against the brand's real ones, which for Honey are joinhoney.com and paypal.com. If you downloaded and ran the file, act on the risk immediately: from a clean device, change your Google password, revoke every session, and remove any channel access you do not recognize.