Researchers from Cado Security Labs have identified a sophisticated spearphishing campaign using compromised Japanese business email accounts to impersonate Docusign and steal sensitive corporate login credentials from executives.
Key Points
- Attackers use compromised Japanese domains to bypass DMARC checks and improve email deliverability by leveraging high-reputation sender addresses.
- Phishing emails mimic legitimate Docusign branding and often include fake email threads to deceive recipients into clicking malicious links.
- Technical analysis revealed obfuscated JavaScript scripts designed to redirect users through fake Google Workspace login pages to harvest credentials.
- Malicious infrastructure identified in the campaign includes domains such as "yperbole9[.]com" and "blegabouc[.]com" used to host credential-stealing portals.
- The campaign specifically targets tech executives to gain access for further business email compromise (BEC) attacks or to sell stolen data on illicit marketplaces.