AUTO-UPDATED

The Growing Threat of Docusign Phishing Attacks

Researchers from Cado Security Labs have identified a sophisticated spearphishing campaign using compromised Japanese business email accounts to impersonate Docusign and steal sensitive corporate login credentials from executives.

Key Points

  • Attackers use compromised Japanese domains to bypass DMARC checks and improve email deliverability by leveraging high-reputation sender addresses.
  • Phishing emails mimic legitimate Docusign branding and often include fake email threads to deceive recipients into clicking malicious links.
  • Technical analysis revealed obfuscated JavaScript scripts designed to redirect users through fake Google Workspace login pages to harvest credentials.
  • Malicious infrastructure identified in the campaign includes domains such as "yperbole9[.]com" and "blegabouc[.]com" used to host credential-stealing portals.
  • The campaign specifically targets tech executives to gain access for further business email compromise (BEC) attacks or to sell stolen data on illicit marketplaces.

Why it Matters

These attacks exploit the high level of trust organizations place in electronic signature platforms to bypass standard security filters. By compromising legitimate business accounts, attackers significantly increase the risk of successful data breaches and subsequent corporate financial fraud.
Darktrace.com Published by Tara Gould
Read original