From E-Sign to RMM: DocuSign Kit Targets Windows and...
Essential information
- Published
- 21/07/2026 13:38
- Modified
- —
- Source / Author
- AlienVault
- Confidence
- 100/100
- Report type(s)
- threat-report
- Labels / Tags
- cloudflare turnstile docusign phishing macos targeting meshagent rmm abuse screenconnect simplehelp uemsagent vbs deployment windows defender evasion
- Related entities
- 8 indicators, 6 observables, 10 techniques (mitre), 4 malware
Description
A sophisticated phishing campaign leverages DocuSign-themed lures to trick victims into installing legitimate remote management software including MeshAgent, ScreenConnect, and SimpleHelp. The operation employs a reusable web kit featuring staged delivery through simulated document loading interfaces, user-agent based targeting that filters for Windows systems while blocking Edge browsers, and Cloudflare Turnstile verification. The campaign demonstrates operational maturity with separate Windows and macOS delivery paths, real-time victim telemetry via Telegram, and VBS deployment scripts that disable Windows Defender and establish persistence through service installation. Active from May through July 2026, the infrastructure rotates across multiple domains using consistent URL patterns to evade detection while abusing trusted IT tools for persistent access.