Cado Security Labs(现为Darktrace旗下)发现了一项针对科技行业高管的DocuSign矛鱼式邮件活动 [1]。攻击者冒充DocuSign发送恶意邮件,邮件中包含重定向到虚假登录页面的链接,意图窃取用户凭证 [1]。被盗凭证随后被用于商业电子邮件欺诈(BEC)等后续攻击 [1]。
此次活动的技术特征表明攻击者采用了多层欺骗手段 [1]。攻击者利用被入侵的日本企业邮箱域名(包括@anabuki-enter.co.jp和@jaog.or.jp)发送钓鱼邮件,以此规避DMARC安全检查 [1]。恶意邮件中的JavaScript代码经过base64编码混淆,脚本名称为NdoGg8EElI,用于伪造合法的DocuSign登录界面 [1]。钓鱼网站则托管在blegabouc[.]com和yperbole9[.]com两个域名上 [1]。
为防范此类威胁,安全建议包括启用双因素认证、验证发件人真实身份、对未通过SPF/DKIM/DMARC验证的邮件进行标记,以及直接通过DocuSign账户而非邮件链接验证文件真实性 [1]。
Cado Security Labs, now part of Darktrace, has identified a sophisticated phishing campaign leveraging fraudulent DocuSign emails to target technology industry executives [1]. The attackers exploit compromised Japanese business email accounts to send malicious messages containing links that redirect victims to credential-harvesting websites, bypassing DMARC authentication checks in the process [1].
The campaign employs obfuscated JavaScript code, including a script named NdoGg8EElI encoded in base64, to create fake login pages designed to steal user credentials [1]. The phishing domains used in the attacks include blegabouc[.]com and yperbole9[.]com [1]. Once credentials are obtained, threat actors use the stolen information to conduct further attacks, including business email compromise (BEC) schemes [1].
To mitigate exposure to this threat, security experts recommend enabling two-factor authentication, carefully verifying sender addresses before responding to DocuSign communications, flagging emails that fail SPF, DKIM, and DMARC verification, and validating document authenticity directly through DocuSign accounts [1].