logo

Living Off the Land: Credential Phishing via Docusign abuse · Blog · Sublime Security

ID: 4d008933-16b4-5326-af28-c1c720c7f54d

STIX ID: report--4d008933-16b4-5326-af28-c1c720c7f54d

Feed Name: Sublime Security Blog

Threat Score
60/100

Date Published: 2026-01-09

Date Updated: 2026-05-01

...
...

This Attack Spotlight describes a credential-phishing campaign that leverages legitimate DocuSign landing pages and PDFs to deliver multistage redirects to fake Microsoft login pages (including QR-code obfuscation). The report highlights attacker tactics—high-reputation domain abuse, link redirects, and use of CAPTCHAs to evade automated analysis—and outlines detection signals and Sublime Security's prevention capabilities.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.