logo

The Zoho Sign Request That Passed Every Check Except the Reply-To: Government Impersonation via E-Sign Infrastructure

ID: d218cb19-5053-5c9f-b91c-2970ddfb563c

STIX ID: report--d218cb19-5053-5c9f-b91c-2970ddfb563c

Feed Name: IRONSCALES

Threat Score
70/100

Date Published: 2026-05-26

Date Updated: 2026-05-26

Author: [email protected] (Audian Paxson)

...
...

A high-severity phishing campaign abused Zoho Sign's authenticated delivery to send convincing document-signing requests that used a legitimate Zoho sender and links but contained a deceptive Reply-To/in-message sender ([email protected]) tied to an unverifiable domain; the report provides IOCs, behavioral detection rationale, and MITRE mappings highlighting credential harvesting and impersonation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.