Fake Microsoft Quarantine Hides a DocuSign NDA Trap
ID: 7aa19ea0-166b-51f8-adc4-043f8fbcaa38
STIX ID: report--7aa19ea0-166b-51f8-adc4-043f8fbcaa38
Feed Name: IRONSCALES
An attacker staged a credential‑harvesting phishing campaign by cloning a Microsoft quarantine UI and embedding a fake DocuSign NDA; the CTA link was hidden behind a chain of legitimate URL‑rewriters that resolved to flagged domains (notably scale.kusbilisim.com and signatureforemail.com). The emails originated from a compromised Amazon SES account and passed SPF/DKIM/DMARC, highlighting identity/infrastructure abuse; the messages were auto‑quarantined based on behavioral signals and the report provides IoCs and MITRE mappings.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
