Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

From E-Sign to RMM: DocuSign Kit Targets Windows and...

0
Medium
Published: 07/21/2026 (07/21/2026, 11:38:33 UTC)
Source: AlienVault OTX General

Description

A phishing campaign impersonates DocuSign to trick victims into installing legitimate remote management software such as MeshAgent, ScreenConnect, and SimpleHelp. It uses a reusable web kit with staged delivery, user-agent filtering targeting Windows systems (excluding Edge browsers), and Cloudflare Turnstile verification. The campaign features separate delivery paths for Windows and macOS, disables Windows Defender via VBS scripts, and establishes persistence through service installation. Active from May to July 2026, it rotates infrastructure across multiple domains to evade detection while abusing trusted IT tools for persistent access.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/21/2026, 22:53:46 UTC

Technical Analysis

This threat involves a sophisticated phishing operation leveraging DocuSign-themed lures to deliver legitimate remote management software (MeshAgent, ScreenConnect, SimpleHelp) to victims. The attackers use a modular web kit that stages payload delivery through simulated document loading interfaces and filters targets based on user-agent strings to focus on Windows systems while blocking Microsoft Edge browsers. Cloudflare Turnstile is used for bot mitigation. The campaign supports both Windows and macOS delivery paths and employs VBS deployment scripts that disable Windows Defender and install services to maintain persistence. Real-time victim telemetry is sent via Telegram. The infrastructure is actively rotated across multiple domains with consistent URL patterns to avoid detection. The campaign abuses trusted IT management tools for persistent access and has been active from May through July 2026.

Potential Impact

Victims may be tricked into installing legitimate remote management software that is abused by attackers to maintain persistent access to compromised systems. The campaign disables Windows Defender, which reduces endpoint protection effectiveness, and establishes persistence via service installation. The use of trusted IT tools complicates detection and response. Both Windows and macOS systems are targeted, increasing the potential victim pool. The infrastructure rotation and use of Cloudflare Turnstile make detection and blocking more difficult.

Mitigation Recommendations

No official patch or fix is applicable as this is a phishing and malware delivery campaign rather than a software vulnerability. Defenders should focus on user awareness training to recognize phishing lures, especially those impersonating DocuSign. Network and endpoint detection should monitor for installation and execution of MeshAgent, ScreenConnect, SimpleHelp, and suspicious VBS scripts disabling Windows Defender or installing services. Blocking known malicious domains and URLs associated with this campaign can help reduce exposure. Since the campaign uses Cloudflare Turnstile and rotates domains, continuous threat intelligence updates are recommended. There is no vendor-managed remediation as this is not a cloud service vulnerability.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://www.bluevoyant.com/blog/docusign-phishing-kit-rmm-analysis"]
Adversary
null
Pulse Id
6a5f5a391cc670d0388a1d29
Threat Score
null

Indicators of Compromise

Hash

ValueDescriptionCopy
hash2a206b085fedf8b20d1db883814c15e0202617da223dbb4e28b7109df98645df
hash4f1c8de304a855c2a4d1995b41069641dee84f1b51b6fb4a6e24eee59c6a30e4

Url

ValueDescriptionCopy
urlhttps://rosetomaz.com.br/it/
urlhttps://spearbit.com/license/check.php?...
urlhttps://spearbit.com/meshagents?...

Domain

ValueDescriptionCopy
domaini8reactorsee.xyz
domainmagroys.lat
domainrosetomaz.com.br

Threat ID: 6a5ff4af9c2644c7f8e0c5d3

Added to database: 07/21/2026, 22:37:35 UTC

Last enriched: 07/21/2026, 22:53:46 UTC

Last updated: 07/21/2026, 22:53:46 UTC

Views: 2

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses