Hasty Briefsbeta

Bilingual

The Growing Threat of Docusign Phishing Attacks

9 hours ago
  • Cado Security Labs (now part of Darktrace) identified a DocuSign spearphishing campaign targeting tech executives, using compromised Japanese business emails and obfuscated JavaScript to steal credentials for BEC scams.
  • The campaign leverages legitimate compromised email accounts and marketing services to bypass security checks, with malicious links redirecting users to credential-stealing pages mimicking Google Workspace logins.
  • A separate multi-stage ransomware attack detected by Darktrace in 2026 involved compromised VPN credentials, Sliver framework for C2, and LOTL techniques (PSExec, WMI, RDP) leading to data exfiltration via Wasabi and encryption via SMBv1.
  • Darktrace recommends behavioral anomaly detection, 2FA, employee phishing education, and verifying DocuSign documents through official portals to defend against such attacks.
  • New Darktrace/EMAIL capabilities include Inbox Analysis highlighting suspicious content, Just-In-Time Training Banners, Custom Sensitive Data Detection, and Workflow Risk Posture Dashboards for cross-channel security.