DocuSign Phishing Kit Delivers RMM Tools to Windows and macOS 

Phishing campaigns are increasingly shifting away from traditional malware in favor of trusted business applications and legitimate IT tools. 

Research from BlueVoyant shows attackers are using realistic DocuSign-themed pages to trick users into installing legitimate remote monitoring and management (RMM) software. 

By abusing trusted administrative tools, the attackers can establish persistent access to Windows and macOS systems while making malicious activity more difficult to detect. 

Key takeaways of the DocuSign phishing kit campaign

  • Attackers are using realistic DocuSign-themed phishing pages to deliver legitimate remote management and monitoring (RMM) software instead of traditional malware.
  • The phishing kit uses staged document-loading screens, user-agent checks, and Cloudflare Turnstile verification to increase legitimacy before delivering the payload.
  • The campaign rotates among trusted administration tools, including MeshAgent, ScreenConnect, SimpleHelp, and Zoho ManageEngine UEMSAgent, to establish persistent remote access.
  • Researchers observed the reusable phishing framework targeting both Windows and macOS across numerous domains, indicating a scalable, multi-platform campaign.
  • Organizations should strengthen visibility into remote management software, script activity, and software deployment while restricting unauthorized RMM tools and testing incident response plans.

How the DocuSign phishing campaign works 

According to BlueVoyant, the campaign relies on a reusable phishing kit that closely mimics a legitimate DocuSign document-signing workflow. 

Rather than immediately prompting users to download a file, the attackers guide victims through a carefully staged experience designed to build trust and reduce suspicion before delivering the payload.

Fake document viewer builds trust 

The attack begins with a fake PDF viewer that closely resembles Adobe Acrobat. 

Victims are presented with what appears to be a secure document-loading interface featuring a progress bar, document preview, navigation panel, and an “Open in Acrobat” button. 

Although no document is actually processed or displayed, the interface uses animations and timed transitions to convince users that a legitimate document is being prepared for viewing.

User-agent checks filter potential victims 

Once the simulated loading process finishes, the phishing page evaluates the visitor’s environment before allowing the workflow to continue. 

The kit inspects the browser’s user-agent string to identify the operating system and browser, permitting only selected environments to proceed. 

Windows users are allowed to continue, while unsupported platforms receive convincing error messages. 

Microsoft Edge users are specifically redirected to a page recommending Chrome, Firefox, or Opera, likely to avoid SmartScreen protections or ensure compatibility with the attackers’ preferred execution path.

Cloudflare verification precedes payload delivery 

After passing these validation checks, victims are presented with a professional-looking DocuSign interface that requires completion of a Cloudflare Turnstile verification before the download button becomes active. 

This additional verification step reinforces the appearance of a legitimate document-signing process while helping the operators filter automated traffic.

Before initiating the download, the phishing infrastructure collects telemetry including the victim’s public IP address, browser details, timestamp, and selected filename. 

This information is transmitted to the attackers through the Telegram Bot API, providing near real-time notification whenever a victim reaches the download stage.

How the DocuSign phishing kit uses legitimate RMM tools 

Unlike many phishing campaigns that distribute malware, this operation delivers legitimate remote monitoring and management (RMM) software to establish persistent access. 

Throughout the campaign, BlueVoyant observed the attackers rotating among legitimate administration tools, including MeshAgent, ScreenConnect, SimpleHelp, and Zoho ManageEngine UEMSAgent. 

Because these applications are widely deployed by enterprise IT teams, they can blend into normal administrative activity, making malicious installations more difficult to detect.

The campaign initially delivered a Visual Basic Script (VBS) installer before shifting to ScreenConnect installers hosted on Dropbox, demonstrating the operators’ evolving delivery methods. 

How the VBS script deploys remote management software 

BlueVoyant’s analysis found that the VBS file functions primarily as an automated deployment utility rather than standalone malware. 

If administrative privileges are unavailable, the script requests User Account Control (UAC) elevation before validating a remote deployment key controlled by the attackers.

The script attempts to disable Microsoft Defender real-time monitoring and add antivirus exclusions, although these actions may be blocked by Defender Tamper Protection or centralized security policies. 

It also removes any existing MeshAgent installation before downloading and installing a replacement version.

Rather than implementing its own persistence mechanism, the script relies on MeshAgent’s native Windows service to automatically restart after system reboots. 

This allows attackers to maintain long-term remote access while blending into legitimate enterprise administration. 

DocuSign phishing campaign targets Windows and macOS 

BlueVoyant’s broader telemetry indicates this is not an isolated phishing operation but a sustained campaign active from at least May through July 2026. 

Researchers identified the reusable DocuSign phishing kit across numerous unrelated domains that shared consistent staging logic, URL structures, and delivery workflows. 

This suggests the operators are using a scalable phishing framework rather than creating individual phishing pages for each campaign. 

The research also shows the operators expanded beyond Windows by incorporating dedicated Windows and macOS delivery paths into the phishing kit. 

Combined with their rotation among legitimate RMM platforms, this evolution demonstrates a mature operation that continuously adapts its infrastructure and tooling. 

How organizations can reduce the risk of DocuSign phishing attacks 

Because legitimate remote management software plays an important role in enterprise IT, organizations should focus on detecting unusual installation activity rather than simply blocking these applications outright. 

  • Allow only approved remote management and endpoint management tools through application allowlisting and centralized software deployment.
  • Monitor for unauthorized installation or execution of remote management software and unexpected outbound connections to remote access infrastructure.
  • Detect suspicious script activity, including wscript.exe launching PowerShell, attempts to disable security controls, or changes to Microsoft Defender settings.
  • Enable Microsoft Defender Tamper Protection and alert on antivirus exclusions or other unauthorized security configuration changes.
  • Train users to independently verify unexpected DocuSign or e-signature requests through secondary, trusted communication channels before downloading files.
  • Maintain an inventory of authorized remote access tools and regularly investigate new services or unmanaged remote management agents.
  • Test incident response plans for phishing attack scenarios involving legitimate remote management tools to validate detection, containment, and recovery procedures.

Collectively, these measures can help organizations reduce overall exposure and build resilience.

Bottom line

The research highlights how phishing campaigns continue to abuse trusted workflows and legitimate administrative tools. 

Organizations should ensure their security programs include visibility into remote management software, script activity, and software deployment alongside traditional malware detection. 

As attackers increasingly exploit trusted applications and identities, organizations are strengthening their defenses with Zero Trust solutions that help continuously verify users, devices, and access requests.

Similar Posts

Leave a Reply