{"id":3577,"date":"2024-05-15T15:35:03","date_gmt":"2024-05-15T20:35:03","guid":{"rendered":"https:\/\/www.darkreading.com\/threat-intelligence\/scammers-fake-docusign-templates-blackmail-steal-companies"},"modified":"2024-05-15T15:35:03","modified_gmt":"2024-05-15T20:35:03","slug":"scammers-fake-docusign-templates-to-blackmail-steal-from-companies","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/05\/15\/scammers-fake-docusign-templates-to-blackmail-steal-from-companies\/","title":{"rendered":"Scammers Fake DocuSign Templates to Blackmail &amp; Steal From Companies"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/bltbb46cb8a3aac7e9a\/64f15456a720e87c12bc392b\/Phishing_Andrea_Danti_Alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/scammers-fake-docusign-templates-to-blackmail-steal-from-companies.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Phishing emails mimicking DocuSign are rising, thanks to a thriving underground marketplace for fake templates and login credentials.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Over the past month, researchers from Abnormal Security claim to have tracked a <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/abnormalsecurity.com\/blog\/cybercriminals-exploit-docusign\" rel=\"noopener\">significant increase in phishing attacks<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> designed to mimic legitimate DocuSign requests. A quick trip down the rabbit hole took them to a Russian cybercrime forum, where sellers peddled a variety of templates resembling authentic emails and documents.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Phishing's Underground Market\">Phishing&#8217;s Underground Market<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The market&#8217;s leading document-signing software has long provided <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/endpoint-security\/docusign-s-brand-used-in-phishing-attacks\" rel=\"noopener\">fertile grounds for phishermen<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">. Its popularity helps, and that it&#8217;s often used to store and transfer valuable documents with sensitive data. DocuSign emails tend to be generic, making them <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/docusign-phishing-campaign-uses-covid-19-as-bait\" rel=\"noopener\">a cinch to forge<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, with a big, yellow button beckoning users to click before they think twice about it.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Everybody&#8217;s been conditioned \u2014 especially after some time in the workplace \u2014 that DocuSign links look a certain way,&#8221; explains Mike Britton, CISO of Abnormal Security. &#8220;It&#8217;s got the blue background, the &#8216;DocuSign&#8217; logo, that [characteristic] look and feel. In any given week I probably deal with half a dozen different things that I have to sign for DocuSign \u2014 whether it&#8217;s from a vendor, a partner, whatever \u2014 I&#8217;m kind of conditioned to see it, click it, and kind of go into autopilot.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">To achieve that perfect look and feel necessary to lull victims into autopilot, an attacker might take the time to craft legitimate-looking DocuSign email and document templates from scratch. Amateur, lazy, overworked, or simply logical and efficient hackers might instead purchase ready-made malicious ones from online marketplaces. After all, Britton says, the cost of a fresh template for DocuSign, Amazon, PayPal, and more run as little as US $10.<\/span><\/p>\n<div readability=\"7\"><img decoding=\"async\" data-testid=\"content-image\" data-component=\"image\" class=\"ContentImage-Image ContentImage-Image_align_left\" data-src=\"https:\/\/abnormalsecurity.com\/_next\/image?url=https%3A%2F%2Foptimise2.assets-servd.host%2Fgifted-zorilla%2Fproduction%2Fimages%2Fblog%2FDocusign2.png%3Fw%3D1536%26h%3D799%26auto%3Dcompress%252Cformat%26fit%3Dcrop%26dm%3D1715717607%26s%3Dce21586415c44a722165eb1601a45d48&amp;w=3840&amp;q=75&amp;width=700&amp;auto=webp&amp;quality=80&amp;disable=upscale\" src=\"https:\/\/abnormalsecurity.com\/_next\/image?url=https%3A%2F%2Foptimise2.assets-servd.host%2Fgifted-zorilla%2Fproduction%2Fimages%2Fblog%2FDocusign2.png%3Fw%3D1536%26h%3D799%26auto%3Dcompress%252Cformat%26fit%3Dcrop%26dm%3D1715717607%26s%3Dce21586415c44a722165eb1601a45d48&amp;w=3840&amp;q=75&amp;width=700&amp;auto=webp&amp;quality=80&amp;disable=upscale\" loading=\"lazy\" alt=\"An email from DocuSign that is a scam\" title=\"An email from DocuSign that is a scam\"><\/p>\n<p class=\"ContentImage-Link\">Source: Abnormal Security<\/p>\n<\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">With such a cheap resource in hand, attackers can craft phishing emails that trick employees of targeted organizations in any number of ways. They can send fake documents with prompts for users to enter their personally identifying information (PII), for example, or they can redirect users to fake login pages for submitting their real DocuSign login credentials. Then they can leverage the data they obtain or, more likely, sell it on to the next buyer in the food chain.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">As Britton says, &#8220;We&#8217;re long gone from the days where cybercriminals own the entire lifecycle [of an attack]. Now, if I want to go attack 10,000 victims and steal money from them, I&#8217;m just going to go buy credentials, [and] buy access \u2014 the necessary assets to shortcut it.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">So besides email and document templates, there&#8217;s also a thriving market for the login credentials that phishers glean. And here is where the attacks start to get ugly.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"The Consequence to Companies\">The Consequence to Companies<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">With cheap login credentials, hackers can probe employees&#8217; DocuSign histories for all the sensitive documentation they&#8217;ve engaged with in recent months. They can use information from employer contracts, vendor agreements, and payment information as fodder for blackmail in extortion attacks, or they can sell it to attackers even further down the line. They can also use it to identify new, higher-value targets, and impersonate specific individuals at a company or partner company.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">For example, an attacker can time out a request for remittance around the time a company typically pays its vendor every month. Using information from a compromised employee&#8217;s DocuSign history, they can impersonate a direct superior, or a vendor finance department&#8217;s point person, and attach specific, real documents to the email for reference.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">To prevent this, or any number of other potential worst-case scenarios, Abnormal Security recommends that employees always look out for suspicious email sender and link addresses, impersonal email greetings, and uncharacteristically short DocuSign security codes, and open documents directly from the company&#8217;s website rather than via email. And, finally, don&#8217;t open documents you&#8217;re not expecting.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Everybody&#8217;s busy,&#8221; Britton acknowledges. &#8220;Whether you&#8217;re in the office, or a hybrid work environment where you&#8217;ve got personal life coming at you, the safest bet is to just pick up the phone and say: &#8216;Hey, I just got this email from you. Is it legit?'&#8221;<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/threat-intelligence\/scammers-fake-docusign-templates-blackmail-steal-companies\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Phishing emails mimicking DocuSign are rising, thanks to a thriving<\/p>\n","protected":false},"author":12,"featured_media":3578,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-3577","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/scammers-fake-docusign-templates-to-blackmail-steal-from-companies.jpg?fit=1200%2C900&ssl=1",1200,900,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/scammers-fake-docusign-templates-to-blackmail-steal-from-companies.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/scammers-fake-docusign-templates-to-blackmail-steal-from-companies.jpg?fit=300%2C225&ssl=1",300,225,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/scammers-fake-docusign-templates-to-blackmail-steal-from-companies.jpg?fit=640%2C480&ssl=1",640,480,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/scammers-fake-docusign-templates-to-blackmail-steal-from-companies.jpg?fit=640%2C480&ssl=1",640,480,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/scammers-fake-docusign-templates-to-blackmail-steal-from-companies.jpg?fit=1200%2C900&ssl=1",1200,900,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/scammers-fake-docusign-templates-to-blackmail-steal-from-companies.jpg?fit=1200%2C900&ssl=1",1200,900,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/scammers-fake-docusign-templates-to-blackmail-steal-from-companies.jpg?fit=1024%2C768&ssl=1",1024,768,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/scammers-fake-docusign-templates-to-blackmail-steal-from-companies.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/scammers-fake-docusign-templates-to-blackmail-steal-from-companies.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/scammers-fake-docusign-templates-to-blackmail-steal-from-companies.jpg?fit=1200%2C900&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3577","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=3577"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3577\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/3578"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=3577"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=3577"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=3577"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}