216.73.217.24

From E-Sign to RMM: DocuSign Kit Targets Windows and...

· Published 21/07/2026 13:38

Export JSON

Essential information

Published
21/07/2026 13:38
Modified
Source / Author
AlienVault
Confidence
100/100
Report type(s)
threat-report
Labels / Tags
cloudflare turnstile docusign phishing macos targeting meshagent rmm abuse screenconnect simplehelp uemsagent vbs deployment windows defender evasion
Related entities
8 indicators, 6 observables, 10 techniques (mitre), 4 malware

Description

A sophisticated phishing campaign leverages DocuSign-themed lures to trick victims into installing legitimate remote management software including , , and . The operation employs a reusable web kit featuring staged delivery through simulated document loading interfaces, user-agent based targeting that filters for Windows systems while blocking Edge browsers, and verification. The campaign demonstrates operational maturity with separate Windows and macOS delivery paths, real-time victim telemetry via Telegram, and VBS deployment scripts that disable Windows Defender and establish persistence through service installation. Active from May through July 2026, the infrastructure rotates across multiple domains using consistent URL patterns to evade detection while abusing trusted IT tools for persistent access.

External references