ScreenConnect as malware via Canva abuse and Docusign impersonation · Blog · Sublime Security
ID: 41d7cd85-4314-5ece-a0c0-a373b01056d2
STIX ID: report--41d7cd85-4314-5ece-a0c0-a373b01056d2
Feed Name: Sublime Security Blog
Sublime’s Threat Research details an ongoing email campaign that leverages Canva-hosted pages to deliver credential phishing and to distribute a legitimately signed ScreenConnect installer with malicious overlay configuration that installs a remote-access service. The report includes examples of email lures (DocuSign impersonation and direct links), encrypted JavaScript CAPTCHA pages that decrypt phishing logic, IOCs (malicious domain relay.shamrockkfoods.com, IP 23.226.68.20, Cloudflare R2 download URL), and detection signals used to identify the attacks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
