New DocuSign-Themed Phishing Scam Delivers Stealth Malware to Windows Devices
## Phishing Campaign Exploits DocuSign Brand to Distribute Malware
Phishing Campaign Exploits DocuSign Brand to Distribute Malware
Recent findings reveal a sophisticated phishing campaign leveraging DocuSign's branding to disseminate Vidar malware, targeting Windows systems.
The campaign initiates with a phishing email impersonating DocuSign, urging recipients to review a document. The email directs users to a counterfeit domain, docu[.]sign-platform[.]app, which mimics the official DocuSign site to increase the credibility of the malicious page.
Once on the fraudulent site, users are prompted to download DocuSign_PackageInstaller.exe, falsely presented as a legitimate DocuSign package.
Fake Signed Installer and Execution Barriers
The downloaded installer is a .NET bundle signed with a valid code-signing certificate from a Chinese company, aiming to bypass reputation checks. Upon execution, the program verifies an access code and communicates with a command and control server. If validated, the malware proceeds to the next stage, preventing analysis by automated systems.
Recent findings reveal a sophisticated phishing campaign leveraging DocuSign's branding to disseminate Vidar malware, targeting Windows systems.
The binary includes a URL and second-stage loader, allowing analysts to reconstruct the malware delivery chain. The second-stage payload is a Windows binary incorporating a time-based execution barrier using an online time source, thwarting local clock manipulation.
The malware employs packing and layered obfuscation to hinder reverse engineering and detection. Under appropriate conditions, it deploys Vidar, an information-stealing malware targeting browser data, credentials, cryptocurrency wallets, and other sensitive information.
This campaign exemplifies the blending of trusted brands, realistic phishing pages, legitimate code-signing certificates, access code-gated logic, and online time checks to evade automated detection, enhancing the likelihood of successful compromise.
Use of trusted brands and convincing phishing pages Deployment of legitimate code-signing certificates Access code-gated command and control logic Incorporation of online time checks and packing
Based on reporting by GBHackers.
