logo

Sign Here, Get Phished: Inside an Adobe Sign Lure With a Multi-Hop Redirect to Credential Theft

ID: 1ba9b795-1515-556c-ad1b-85c1a13aeacc

STIX ID: report--1ba9b795-1515-556c-ad1b-85c1a13aeacc

Feed Name: IRONSCALES

Threat Score
70/100

Date Published: 2026-04-22

Date Updated: 2026-04-28

Author: [email protected] (Audian Paxson)

...
...

A high-risk phishing campaign impersonating Adobe Sign used mixed Adobe/AdobeSign CTAs and multi-hop proxied redirects to land victims on a credential-harvesting page at the privacy-masked domain fameklinik.com (registered 2022); IRONSCALES' Adaptive AI detected and quarantined the message before credentials were captured, and the report lists the harvesting domain, WHOIS privacy, branding inconsistencies, external first-time sender, and MITRE techniques T1566.001, T1036.005, and T1204.001 as key indicators.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.