Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

From E-Sign to RMM: DocuSign Kit Targets Windows and...

0
Medium
Published: 07/21/2026 (07/21/2026, 11:38:33 UTC)
Source: AlienVault OTX General

Description

A sophisticated phishing campaign leverages DocuSign-themed lures to trick victims into installing legitimate remote management software including MeshAgent, ScreenConnect, and SimpleHelp. The operation employs a reusable web kit featuring staged delivery through simulated document loading interfaces, user-agent based targeting that filters for Windows systems while blocking Edge browsers, and Cloudflare Turnstile verification. The campaign demonstrates operational maturity with separate Windows and macOS delivery paths, real-time victim telemetry via Telegram, and VBS deployment scripts that disable Windows Defender and establish persistence through service installation. Active from May through July 2026, the infrastructure rotates across multiple domains using consistent URL patterns to evade detection while abusing trusted IT tools for persistent access.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/21/2026, 22:53:46 UTC

Technical Analysis

This threat involves a sophisticated phishing operation leveraging DocuSign-themed lures to deliver legitimate remote management software (MeshAgent, ScreenConnect, SimpleHelp) to victims. The attackers use a modular web kit that stages payload delivery through simulated document loading interfaces and filters targets based on user-agent strings to focus on Windows systems while blocking Microsoft Edge browsers. Cloudflare Turnstile is used for bot mitigation. The campaign supports both Windows and macOS delivery paths and employs VBS deployment scripts that disable Windows Defender and install services to maintain persistence. Real-time victim telemetry is sent via Telegram. The infrastructure is actively rotated across multiple domains with consistent URL patterns to avoid detection. The campaign abuses trusted IT management tools for persistent access and has been active from May through July 2026.

Potential Impact

Victims may be tricked into installing legitimate remote management software that is abused by attackers to maintain persistent access to compromised systems. The campaign disables Windows Defender, which reduces endpoint protection effectiveness, and establishes persistence via service installation. The use of trusted IT tools complicates detection and response. Both Windows and macOS systems are targeted, increasing the potential victim pool. The infrastructure rotation and use of Cloudflare Turnstile make detection and blocking more difficult.

Defensive Guidance

No official patch or fix is applicable as this is a phishing and malware delivery campaign rather than a software vulnerability. Defenders should focus on user awareness training to recognize phishing lures, especially those impersonating DocuSign. Network and endpoint detection should monitor for installation and execution of MeshAgent, ScreenConnect, SimpleHelp, and suspicious VBS scripts disabling Windows Defender or installing services. Blocking known malicious domains and URLs associated with this campaign can help reduce exposure. Since the campaign uses Cloudflare Turnstile and rotates domains, continuous threat intelligence updates are recommended. There is no vendor-managed remediation as this is not a cloud service vulnerability.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://www.bluevoyant.com/blog/docusign-phishing-kit-rmm-analysis"]
Adversary
null
Pulse Id
6a5f5a391cc670d0388a1d29
Threat Score
null

Indicators of Compromise

Hash

ValueDescriptionCopy
hash2a206b085fedf8b20d1db883814c15e0202617da223dbb4e28b7109df98645df
hash4f1c8de304a855c2a4d1995b41069641dee84f1b51b6fb4a6e24eee59c6a30e4

Url

ValueDescriptionCopy
urlhttps://rosetomaz.com.br/it/
urlhttps://spearbit.com/license/check.php?...
urlhttps://spearbit.com/meshagents?...

Domain

ValueDescriptionCopy
domaini8reactorsee.xyz
domainmagroys.lat
domainrosetomaz.com.br

Threat ID: 6a5ff4af9c2644c7f8e0c5d3

Added to database: 07/21/2026, 22:37:35 UTC

Last enriched: 07/21/2026, 22:53:46 UTC

Last updated: 08/31/2026, 20:05:57 UTC

Views: 104

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses