Hackers Create Fake DocuSign Login Page to Steal User Credentials
ID: cce610ac-951d-5911-95ff-6d3aabed971e
STIX ID: report--cce610ac-951d-5911-95ff-6d3aabed971e
Feed Name: GBHackers
Threat Score
Researchers observed an ongoing DocuSign impersonation phishing campaign that leverages the LogoKit phishing framework and legitimate hosting (IPFS gateways, AWS S3) to dynamically assemble convincing fake login portals that harvest credentials; indicators include SPF failures, mismatched Reply-To headers, and URLs passing recipient emails as parameters, and defenders are advised to enforce SPF/DKIM/DMARC, deploy advanced email protections, and train users.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
