Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

New DocuSign-Themed Phishing Scam Delivers Stealth Malware to Windows Devices

## Phishing Campaign Exploits DocuSign Brand to Distribute Malware

Phishing Campaign Exploits DocuSign Brand to Distribute Malware

Recent findings reveal a sophisticated phishing campaign leveraging DocuSign's branding to disseminate Vidar malware, targeting Windows systems.

The campaign initiates with a phishing email impersonating DocuSign, urging recipients to review a document. The email directs users to a counterfeit domain, docu[.]sign-platform[.]app, which mimics the official DocuSign site to increase the credibility of the malicious page.

Once on the fraudulent site, users are prompted to download DocuSign_PackageInstaller.exe, falsely presented as a legitimate DocuSign package.

Fake Signed Installer and Execution Barriers

The downloaded installer is a .NET bundle signed with a valid code-signing certificate from a Chinese company, aiming to bypass reputation checks. Upon execution, the program verifies an access code and communicates with a command and control server. If validated, the malware proceeds to the next stage, preventing analysis by automated systems.

Recent findings reveal a sophisticated phishing campaign leveraging DocuSign's branding to disseminate Vidar malware, targeting Windows systems.
Harper Fairbanks · Thehackingpost

The binary includes a URL and second-stage loader, allowing analysts to reconstruct the malware delivery chain. The second-stage payload is a Windows binary incorporating a time-based execution barrier using an online time source, thwarting local clock manipulation.

The malware employs packing and layered obfuscation to hinder reverse engineering and detection. Under appropriate conditions, it deploys Vidar, an information-stealing malware targeting browser data, credentials, cryptocurrency wallets, and other sensitive information.

This campaign exemplifies the blending of trusted brands, realistic phishing pages, legitimate code-signing certificates, access code-gated logic, and online time checks to evade automated detection, enhancing the likelihood of successful compromise.

Advertisement

Use of trusted brands and convincing phishing pages Deployment of legitimate code-signing certificates Access code-gated command and control logic Incorporation of online time checks and packing

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories