New DocuSign-Themed Phishing Scam Delivers Stealth Malware to Windows Devices
ID: 299432c5-4caa-57fc-a976-ad33bbc4b81f
STIX ID: report--299432c5-4caa-57fc-a976-ad33bbc4b81f
Feed Name: GBHackers
New research details a DocuSign-branded phishing campaign that lures victims to a lookalike site to download a fake signed installer which, after an access-code verification with a C2 server and time-based checks, loads a packed second-stage binary that ultimately drops the Vidar information-stealer — a malware that targets browser data, credentials and crypto wallets. The chain leverages legitimate code-signing, gated execution, online time checks and layered obfuscation to evade automated sandboxes and delay analysis, increasing the likelihood of successful compromise before defenders can respond.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
