Living Off the Land: Callback Phishing via Docusign comment · Blog · Sublime Security
ID: 11c6d3ad-d3d1-502a-bb00-0228ac0a2580
STIX ID: report--11c6d3ad-d3d1-502a-bb00-0228ac0a2580
Feed Name: Sublime Security Blog
Threat Score
Sublime’s Attack Spotlight describes active callback-phishing campaigns that leverage legitimate DocuSign messages and brand impersonation (e.g., PayPal) to socially engineer recipients into calling attacker-controlled numbers or divulging credentials. The report highlights LOTL service abuse, variants across industries, and detection signals used by Sublime’s AI engine to prevent these email-based attacks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
