HomeSecurityPhishing emails mimic DocuSign to distribute malware

Phishing emails impersonate DocuSign to distribute malware

A new and highly sophisticated wave of phishing attacks is underway, with cybercriminals misusing the DocuSign to distribute malware on Windows systems. The campaign leverages social engineering techniques and various payloads, managing to bypass basic email defenses, antivirus, and automated analysis systems.

DocuSign phishing

How the fake DocuSign email

Phishing emails are carefully crafted to look like genuine DocuSign notifications. They use logos, language, and formatting that refer to the real service and inform the recipient that there is a pending agreement or document to sign. The message prompts the user to click on a link to “review” or “view” the file.

See also: BlueDelta launches attacks to steal login credentials

The simplicity of the message and users' familiarity with DocuSign make the trap particularly effective, especially in professional environments where such notifications are considered everyday.

From browser to multi-stage loader

Clicking on the link doesn't limit the attack to a simple malicious download. Instead, it triggers a multi-stage chainthat transfers activity from the browser to a specialized loader. The goal is to avoid traditional security checks based on known patterns.

The user is taken to a website that asks for a password to display the supposed document. This step is not accidental: on the one hand it reinforces the sense of legitimacy, on the other hand it blocks many automated sandboxes, which cannot proceed without the correct password.

Phishing emails impersonate DocuSign to distribute malware

What's behind the access-code gate?

Behind the page, a dynamic script decides what the next stage of the attack will be. This is usually a download that appears as a harmless PDF or compressed file in the form of a contract. In reality, the file is the “bait” that triggers the infection mechanism.

See also: MFA is required for logins to the Microsoft 365 admin center

JOEsecurity researchers detected and analyzed the malware's behavior using Joe Sandbox Cloud Basic. When executing the samples, they revealed time checks, additional packing, and decryption of the actual payload exclusively in memory.

Execution in memory and detection avoidance

Technical analysis shows that the loader waits for specific time windows before activating, reducing the chances of detection. It then decrypts the main payload only in memory, without storing it on disk, which significantly complicates detection by traditional antiviruses.

The traces of the attack are mainly visible through the process tree and network calls, elements that require advanced monitoring to be detected in a timely manner. The campaign targets vary, from small businesses to large international organizations.

Infection mechanism and PowerShell abuse

When the victim opens the bait file, a small script or macro is executed that launches a command PowerShell. This command downloads the next stage from a remote server under the attackers' control. Encoded strings, environment variables, and execution policy bypass are used to mask the malicious intent.

See also: CrazyHunter ransomware targets healthcare organizations

The script then loads a .NET component directly into memory and executes it. In this way, the malware “hides” inside legitimate system processes.

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Phishing emails impersonate DocuSign to distribute malware

Light persistence, serious danger

To maintain access, the malware adds lightweight persistence mechanisms, such as a Run key in the registry or scheduled tasks that call the script again with new code. While its presence may seem limited, the potential for further infection or data theft remains significant.

Why visibility is critical

Because most of the attack is executed in memory and within trusted processes, experts emphasize that robust endpoint logs, EDR solutions, and network monitoring are essential for early detection. This campaign demonstrates that modern phishing is no longer based solely on user deception, but on complex obfuscation techniques that require equally sophisticated defenses.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS