The DocuSign Lure That Used Google as a Trust Shield (And Encoded Your Email in the Link)
ID: dbb8f24a-02a3-50e9-84cd-84e81506f79c
STIX ID: report--dbb8f24a-02a3-50e9-84cd-84e81506f79c
Feed Name: IRONSCALES
A DocuSign-themed credential harvesting campaign used a google.com/url redirect wrapper to obscure a two-month-old manxo.ink credential page; the CTA contained a base64 token that decoded to each recipient's email, allowing targeted pre-filled login forms and click attribution. The phishing email spoofed a legitimate law firm, originated from an IP that failed SPF, and relied on Microsoft re-signing to achieve passing authentication at delivery; IRONSCALES Themis quarantined the message at 90% confidence. Defenders are advised to dereference redirect chains, score newly registered destination domains higher, and update user training about redirect-wrapped links.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
