Threat Actors Exploit GetShared’s Trust to Evade Detection and Deliver Malware
A new wave of cyberattacks is exploiting the credibility of GetShared—a well-known file-sharing service—to deliver malicious payloads and execute phishing schemes. Instead of relying on traditional spam tactics, attackers are now piggybacking on trusted infrastructure to slip past security defenses.
By leveraging legitimate GetShared notification emails, which many users recognize and trust, attackers sidestep standard email filters and security protocols. These messages often alert recipients that a file has been shared with them—typically under plausible filenames like “DESIGN LOGO.rar”—and appear indistinguishable from genuine communications.
What makes this method especially dangerous is its subtlety: the emails don’t raise red flags because they originate from GetShared’s own domain, using authentic templates and branding. This signals a shift in adversary tactics, as cybercriminals move toward blending in rather than breaking in—exploiting user trust and platform legitimacy rather than brute-force techniques.

Phishing Evolves: GetShared Notifications Used to Deliver Malware
Email disguised as GetShared file notifications (Source: Kaspersky)
Cybercriminals are adapting once again—this time turning to GetShared, a legitimate file-sharing platform, to mask their phishing campaigns under a veil of credibility. The scam emails, formatted to mimic genuine GetShared notifications, often reference pricing, delivery timelines, or payment requests to increase their plausibility and lure victims into clicking.
Kaspersky researchers uncovered this tactic after users began flagging suspicious messages that, on the surface, appeared authentic. Their findings show a rising preference among threat actors for GetShared, especially as platforms like Google Calendar and Dropbox have hardened their defenses.
A New Route Around Security Barriers
What makes this vector so insidious is its ability to bypass email security filters entirely. Because these phishing attempts leverage real notifications from a trusted domain, they often sail through enterprise-level defenses that rely on domain reputation or known bad signatures.
Behind the Click: The Infection Flow
Once a user clicks the “Download” link in the email, they’re redirected to GetShared’s site—where the real attack begins. In some cases, the download is an actual malware payload. In others, users receive a harmless-looking text file with social engineering instructions designed to draw them deeper into the trap.
This multi-layered delivery method allows attackers to sidestep traditional antivirus tools, which are typically focused on identifying known malware signatures. By delaying or disguising the final payload, attackers lower the risk of early detection.
A Shifting Arsenal of Payloads
Even more alarming is the variety of malicious files being deployed. Some attacks use standard executable malware, while others hide harmful scripts inside innocent-looking documents packaged in archive files. This variation makes automated detection more difficult and underscores the need for adaptive security approaches.
Mitigation Strategies
Security professionals recommend bolstering defenses by focusing on behavior-based detection systems and continuous user education. Endpoint protection tools that analyze patterns and anomalies—not just static signatures—are essential in countering this kind of evolving threat.




