logo

ScreenConnect as malware via Canva abuse and Docusign impersonation · Blog · Sublime Security

ID: 41d7cd85-4314-5ece-a0c0-a373b01056d2

STIX ID: report--41d7cd85-4314-5ece-a0c0-a373b01056d2

Feed Name: Sublime Security Blog

Threat Score
75/100

Date Published: 2025-10-22

Date Updated: 2026-05-01

...
...

Sublime’s Threat Research details an ongoing email campaign that leverages Canva-hosted pages to deliver credential phishing and to distribute a legitimately signed ScreenConnect installer with malicious overlay configuration that installs a remote-access service. The report includes examples of email lures (DocuSign impersonation and direct links), encrypted JavaScript CAPTCHA pages that decrypt phishing logic, IOCs (malicious domain relay.shamrockkfoods.com, IP 23.226.68.20, Cloudflare R2 download URL), and detection signals used to identify the attacks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.