Hmmm. It does seem rather confusing, but I still see it as the messages provide a link to Dropbox where the malware is based which then installs it.
I do not see that Dropbox itself is responsible for the email linkys. Could be, however.
It sounds like the got the link to the DropBox site via spam, and then got the macro from there and the macro installed the malware.