Cybercriminals are trying to trick users into installing malware on their computers. Using Dropbox, they instruct recipients to reset their passwords.
According to AppRiver, the fake notifications state: "Hello admin, you recently requested a link to reset your Dropbox password . The old one has now been marked as 'vulnerable'. Please follow the link to reset your password."
Those who click on the link are directed to a fake Microsoft website that instructs users to update their browser.
Updates are available for Chrome, Internet Explorer, and Firefox. In fact, the files are not browser updates, but a version of the infamous data-stealing ZeuS Trojan.
The domain where the malicious site is hosted is dynamooblog.ru. The same domain has been used in a similar spam campaign exploiting Dropbox.
If you encounter such messages, delete them immediately!

