Fake DocuSign email hides tricky phishing attempt
ID: 0bc48d88-985f-5dfe-98cd-0194b3b2f7ca
STIX ID: report--0bc48d88-985f-5dfe-98cd-0194b3b2f7ca
Feed Name: Malwarebytes Blog
Threat Score
This report details a layered DocuSign-themed phishing campaign that weaponized Webflow preview links and randomized redirect domains to perform browser and system fingerprinting via a fake CAPTCHA, then redirected victims to a real Google login page to cloak the operation; while no malware was delivered, the infrastructure and tactics indicate credential harvesting and follow-on targeted attacks are likely.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
