logo

The DocuSign Lure That Used Google as a Trust Shield (And Encoded Your Email in the Link)

ID: dbb8f24a-02a3-50e9-84cd-84e81506f79c

STIX ID: report--dbb8f24a-02a3-50e9-84cd-84e81506f79c

Feed Name: IRONSCALES

Threat Score
70/100

Date Published: 2026-04-08

Date Updated: 2026-04-28

Author: [email protected] (Audian Paxson)

...
...

A DocuSign-themed credential harvesting campaign used a google.com/url redirect wrapper to obscure a two-month-old manxo.ink credential page; the CTA contained a base64 token that decoded to each recipient's email, allowing targeted pre-filled login forms and click attribution. The phishing email spoofed a legitimate law firm, originated from an IP that failed SPF, and relied on Microsoft re-signing to achieve passing authentication at delivery; IRONSCALES Themis quarantined the message at 90% confidence. Defenders are advised to dereference redirect chains, score newly registered destination domains higher, and update user training about redirect-wrapped links.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.