logo

Living Off the Land: Callback Phishing via Docusign comment · Blog · Sublime Security

ID: 11c6d3ad-d3d1-502a-bb00-0228ac0a2580

STIX ID: report--11c6d3ad-d3d1-502a-bb00-0228ac0a2580

Feed Name: Sublime Security Blog

Threat Score
55/100

Date Published: 2025-10-22

Date Updated: 2026-05-01

...
...

Sublime’s Attack Spotlight describes active callback-phishing campaigns that leverage legitimate DocuSign messages and brand impersonation (e.g., PayPal) to socially engineer recipients into calling attacker-controlled numbers or divulging credentials. The report highlights LOTL service abuse, variants across industries, and detection signals used by Sublime’s AI engine to prevent these email-based attacks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.