Target Industry

Indiscriminate, opportunistic targeting. 

Overview 

Threat actors are exploiting DocuSign APIs to send authentic-looking phishing invoices 

Impact 

Threat actors are misusing DocuSign’s Application Programming Interfaces (APIs) to send phishing invoices that bypass traditional spam filters. Legitimate DocuSign accounts and templates, they create highly authentic-looking invoices from well-known brands like Norton. As the fake invoices slip past security measures, more recipients are hooked into making payments. 

Exploitation 

A threat actor has set up paid accounts on the DocuSign platform, allowing them to use official templates and branding, making their communications look authentic. The threat actor is targeting API endpoints such as envelopes.   

The envelopes create the API to automatically generate and send out fake invoices. An API envelope is a wrapping data structure used in APIs to organise and transport data. Since official branding and the emails appear to come from trusted sources, they can bypass email security filters. 

Containment, Mitigations & Remediations 

It is highly recommended to verify the sender of the email by always double-checking the sender’s details. If the charges or invoice requests are unexpected, contact the vendor through trusted channels. Awareness training would be beneficial to highlight these phishing campaigns. 

Indicators of Compromise 

The threat actors have legitimate DocuSign accounts, so they create highly authentic-looking invoices utilising DocuSign templates. There are two Indicators of Comprise (IoCs) to look out for in this phishing campaign: unsolicited emails regarding invoices that require payment and the email address of the sender not matching the company sending the invoice. 

Threat Landscape 

DocuSign holds the dominant position, and is widely used globally, in the electronic signature market. Therefore, this latest phishing campaign is highly critical to users. Users must be vigilant in the receipt of the fake invoices, reporting instances to the vendor being masqueraded. 

 Threat Group 

The specific threat group behind this has not been publicly identified at the time of writing. 

TTPs 

  • T0865 – Spear Phishing Attachment 
  • T1078 – Valid Accounts 
  • T1656 – Impersonation 
  • T1136 – Create Account 

 

Further Information 

https://www.bleepingcomputer.com/news/security/docusigns-envelopes-api-abused-to-send-realistic-fake-invoices/ 

https://hackread.com/scammers-docusign-api-spam-filters-phishing-invoices/ 

https://securityboulevard.com/2024/11/attackers-abuse-docusign-api-to-send-authentic-looking-invoices-at-scale/ 

https://www.infosecurity-magazine.com/news/cybercriminals-exploit-docusign/ 

 

 

Further Threat Intelligence from Quorum Cyber

Headquarters

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

FLORIDA, USA Office

501 E Kennedy Blvd.
STE 1400
Tampa FL 33602

Ontario, Canada Office

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

Contact Us
Address

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

501 E Kennedy Blvd
STE 1400
Tampa FL 33602

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

HEADQUARTERS
Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ



FLORIDA, USA OFFICE
501 E Kennedy Blvd.
STE 1400
Tampa FL 33602


ONTARIO, CANADA OFFICE
1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7


Legal

Privacy Preference Center

Skip to content