From E-Sign to RMM: DocuSign Kit Targets Windows and...
A phishing campaign impersonates DocuSign to trick victims into installing legitimate remote management software such as MeshAgent, ScreenConnect, and SimpleHelp. It uses a reusable web kit with staged delivery, user-agent filtering targeting Windows systems (excluding Edge browsers), and Cloudflare Turnstile verification. The campaign features separate delivery paths for Windows and macOS, disables Windows Defender via VBS scripts, and establishes persistence through service installation. Active from May to July 2026, it rotates infrastructure across multiple domains to evade detection while abusing trusted IT tools for persistent access.
AI Analysis
Technical Summary
This threat involves a sophisticated phishing operation leveraging DocuSign-themed lures to deliver legitimate remote management software (MeshAgent, ScreenConnect, SimpleHelp) to victims. The attackers use a modular web kit that stages payload delivery through simulated document loading interfaces and filters targets based on user-agent strings to focus on Windows systems while blocking Microsoft Edge browsers. Cloudflare Turnstile is used for bot mitigation. The campaign supports both Windows and macOS delivery paths and employs VBS deployment scripts that disable Windows Defender and install services to maintain persistence. Real-time victim telemetry is sent via Telegram. The infrastructure is actively rotated across multiple domains with consistent URL patterns to avoid detection. The campaign abuses trusted IT management tools for persistent access and has been active from May through July 2026.
Potential Impact
Victims may be tricked into installing legitimate remote management software that is abused by attackers to maintain persistent access to compromised systems. The campaign disables Windows Defender, which reduces endpoint protection effectiveness, and establishes persistence via service installation. The use of trusted IT tools complicates detection and response. Both Windows and macOS systems are targeted, increasing the potential victim pool. The infrastructure rotation and use of Cloudflare Turnstile make detection and blocking more difficult.
Mitigation Recommendations
No official patch or fix is applicable as this is a phishing and malware delivery campaign rather than a software vulnerability. Defenders should focus on user awareness training to recognize phishing lures, especially those impersonating DocuSign. Network and endpoint detection should monitor for installation and execution of MeshAgent, ScreenConnect, SimpleHelp, and suspicious VBS scripts disabling Windows Defender or installing services. Blocking known malicious domains and URLs associated with this campaign can help reduce exposure. Since the campaign uses Cloudflare Turnstile and rotates domains, continuous threat intelligence updates are recommended. There is no vendor-managed remediation as this is not a cloud service vulnerability.
Indicators of Compromise
- hash: 2a206b085fedf8b20d1db883814c15e0202617da223dbb4e28b7109df98645df
- hash: 4f1c8de304a855c2a4d1995b41069641dee84f1b51b6fb4a6e24eee59c6a30e4
- url: https://rosetomaz.com.br/it/
- url: https://spearbit.com/license/check.php?...
- url: https://spearbit.com/meshagents?...
- domain: i8reactorsee.xyz
- domain: magroys.lat
- domain: rosetomaz.com.br
From E-Sign to RMM: DocuSign Kit Targets Windows and...
Description
A phishing campaign impersonates DocuSign to trick victims into installing legitimate remote management software such as MeshAgent, ScreenConnect, and SimpleHelp. It uses a reusable web kit with staged delivery, user-agent filtering targeting Windows systems (excluding Edge browsers), and Cloudflare Turnstile verification. The campaign features separate delivery paths for Windows and macOS, disables Windows Defender via VBS scripts, and establishes persistence through service installation. Active from May to July 2026, it rotates infrastructure across multiple domains to evade detection while abusing trusted IT tools for persistent access.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This threat involves a sophisticated phishing operation leveraging DocuSign-themed lures to deliver legitimate remote management software (MeshAgent, ScreenConnect, SimpleHelp) to victims. The attackers use a modular web kit that stages payload delivery through simulated document loading interfaces and filters targets based on user-agent strings to focus on Windows systems while blocking Microsoft Edge browsers. Cloudflare Turnstile is used for bot mitigation. The campaign supports both Windows and macOS delivery paths and employs VBS deployment scripts that disable Windows Defender and install services to maintain persistence. Real-time victim telemetry is sent via Telegram. The infrastructure is actively rotated across multiple domains with consistent URL patterns to avoid detection. The campaign abuses trusted IT management tools for persistent access and has been active from May through July 2026.
Potential Impact
Victims may be tricked into installing legitimate remote management software that is abused by attackers to maintain persistent access to compromised systems. The campaign disables Windows Defender, which reduces endpoint protection effectiveness, and establishes persistence via service installation. The use of trusted IT tools complicates detection and response. Both Windows and macOS systems are targeted, increasing the potential victim pool. The infrastructure rotation and use of Cloudflare Turnstile make detection and blocking more difficult.
Mitigation Recommendations
No official patch or fix is applicable as this is a phishing and malware delivery campaign rather than a software vulnerability. Defenders should focus on user awareness training to recognize phishing lures, especially those impersonating DocuSign. Network and endpoint detection should monitor for installation and execution of MeshAgent, ScreenConnect, SimpleHelp, and suspicious VBS scripts disabling Windows Defender or installing services. Blocking known malicious domains and URLs associated with this campaign can help reduce exposure. Since the campaign uses Cloudflare Turnstile and rotates domains, continuous threat intelligence updates are recommended. There is no vendor-managed remediation as this is not a cloud service vulnerability.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.bluevoyant.com/blog/docusign-phishing-kit-rmm-analysis"]
- Adversary
- null
- Pulse Id
- 6a5f5a391cc670d0388a1d29
- Threat Score
- null
Indicators of Compromise
Hash
| Value | Description | Copy |
|---|---|---|
hash2a206b085fedf8b20d1db883814c15e0202617da223dbb4e28b7109df98645df | — | |
hash4f1c8de304a855c2a4d1995b41069641dee84f1b51b6fb4a6e24eee59c6a30e4 | — |
Url
| Value | Description | Copy |
|---|---|---|
urlhttps://rosetomaz.com.br/it/ | — | |
urlhttps://spearbit.com/license/check.php?... | — | |
urlhttps://spearbit.com/meshagents?... | — |
Domain
| Value | Description | Copy |
|---|---|---|
domaini8reactorsee.xyz | — | |
domainmagroys.lat | — | |
domainrosetomaz.com.br | — |
Threat ID: 6a5ff4af9c2644c7f8e0c5d3
Added to database: 07/21/2026, 22:37:35 UTC
Last enriched: 07/21/2026, 22:53:46 UTC
Last updated: 07/21/2026, 22:53:46 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.