Cado Security Labs, now part of Darktrace, detected a Docusign spearphishing email campaign specifically targeting technology executives. These attacks involve fraudulent emails designed to appear as legitimate Docusign communications, prompting recipients to click links that redirect to credential-stealing websites.
The campaign utilizes compromised legitimate Japanese business email accounts to send the phishing emails. This tactic helps bypass Domain Messaging Authentication Record and Conformance (DMARC) checks, making the emails appear more authentic and less likely to be flagged as spam. One observed email, with the subject “BIYH-QPVSW-3617 is ready for your review” from "@anabuki-enter.co.jp", included a "Review Document Button" linking to "app.getresponse.com", a legitimate marketing service. Another email, from "@jaog.or.jp", contained a link to a malicious website hosting an obfuscated Javascript script named “NdoGg8EElI”, which includes base64 encoded conditional statements.
The use of compromised legitimate email accounts, particularly from domains with higher reputations like those in Japan, makes these phishing attempts more sophisticated and harder to detect. This method increases the likelihood of successful credential theft, which can then be used for further malicious activities. The targeting of tech executives indicates an attempt to gain access to high-value accounts within organizations.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Cado Security Labs identified a Docusign spearphishing campaign targeting tech executives, using emails that mimic legitimate Docusign communications to steal login credentials. The campaign leverages compromised Japanese business email accounts to bypass DMARC checks and increase email deliverability. This highlights an ongoing threat where attackers exploit trusted platforms and compromised accounts to conduct credential harvesting.