logo

New Phishing Attack Impersonate as DocuSign Deploys Stealthy Malware on Windows Systems

ID: 50485352-31dd-5bbc-8513-1e5b07d48255

STIX ID: report--50485352-31dd-5bbc-8513-1e5b07d48255

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2026-01-08

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

A DocuSign-themed phishing wave is delivering a multi-stage Windows malware loader: victims are lured to a gated page that presents an access code, then a downloaded lure triggers an obfuscated PowerShell command which loads a .NET component in memory, injects the main payload into trusted processes, and establishes light persistence via Run keys or scheduled tasks. The campaign employs sandbox-evasion (access-code gate, time-based checks), packing/obfuscation, and in-memory execution to avoid detection, and was analyzed by Joe Sandbox researchers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.