Target Industry
Indiscriminate, opportunistic targeting.
Overview
Threat actors are exploiting DocuSign APIs to send authentic-looking phishing invoices
Impact
Threat actors are misusing DocuSign’s Application Programming Interfaces (APIs) to send phishing invoices that bypass traditional spam filters. Legitimate DocuSign accounts and templates, they create highly authentic-looking invoices from well-known brands like Norton. As the fake invoices slip past security measures, more recipients are hooked into making payments.
Exploitation
A threat actor has set up paid accounts on the DocuSign platform, allowing them to use official templates and branding, making their communications look authentic. The threat actor is targeting API endpoints such as envelopes.
The envelopes create the API to automatically generate and send out fake invoices. An API envelope is a wrapping data structure used in APIs to organise and transport data. Since official branding and the emails appear to come from trusted sources, they can bypass email security filters.
Containment, Mitigations & Remediations
It is highly recommended to verify the sender of the email by always double-checking the sender’s details. If the charges or invoice requests are unexpected, contact the vendor through trusted channels. Awareness training would be beneficial to highlight these phishing campaigns.
Indicators of Compromise
The threat actors have legitimate DocuSign accounts, so they create highly authentic-looking invoices utilising DocuSign templates. There are two Indicators of Comprise (IoCs) to look out for in this phishing campaign: unsolicited emails regarding invoices that require payment and the email address of the sender not matching the company sending the invoice.
Threat Landscape
DocuSign holds the dominant position, and is widely used globally, in the electronic signature market. Therefore, this latest phishing campaign is highly critical to users. Users must be vigilant in the receipt of the fake invoices, reporting instances to the vendor being masqueraded.
Threat Group
The specific threat group behind this has not been publicly identified at the time of writing.
TTPs
- T0865 – Spear Phishing Attachment
- T1078 – Valid Accounts
- T1656 – Impersonation
- T1136 – Create Account
Further Information
https://hackread.com/scammers-docusign-api-spam-filters-phishing-invoices/
https://www.infosecurity-magazine.com/news/cybercriminals-exploit-docusign/













