New Credential Phishing Attack Targeting 10,000 Inboxes Disguised As DocuSign To Exfiltrate Personal Credentials

Armorblox has released its latest research analyzing a credential phishing attack that impersonated the well-known brand, DocuSign, intending to exfiltrate sensitive login credentials.

These emails targeted more than 10,000 end users across multiple organizations and various industries counting on the trust and legitimacy people have in the company.

How it works: In this attack, victims receive an email from what appears to be from DocuSign. 

Attackers instilled a sense of urgency within the body of the email attack to encourage victims to open the new document for review and approval. When clicked, victims were navigated to a fake landing page designed to impersonate a Proofpoint Storage application login.

You can read the research here.

Leave a Reply

Discover more from The IT Nerd

Subscribe now to keep reading and get access to the full archive.

Continue reading