
Telegram Dating Bot Used for Romance-to-Arson Scam
Russia’s FSB claims Ukrainian intelligence used a Telegram dating chatbot to deceive and psychologically pressure young Russians into sharing locations,…
Researchers reported a real spearphishing campaign that impersonates DocuSign emails to trick tech executives into clicking “Review Document” links and entering login details. The emails use compromised legitimate business mailboxes and realistic context (including copied email threads) to appear trustworthy, then route victims to fake Google Workspace/Gmail-style login pages to steal credentials.
This campaign impersonated DocuSign to target tech executives with document-signing lures. One version used a subject line referencing a document ready for review, prompting recipients to click a Review Document button and later enter a security code on what appeared to be Docusign.com. A second version referenced a specific agreement, such as a share transfer and subscription agreement, and included a pasted-in email thread between multiple companies to appear more legitimate. Both variants ultimately led victims to a fake CAPTCHA and a Gmail or Google Workspace lookalike login page designed to harvest credentials.
The emails were sent from compromised legitimate business email accounts rather than newly registered domains. This helped the messages pass DMARC checks and avoid spam filtering, since the sending infrastructure was technically legitimate even though the content was malicious. The use of a real prior email thread added a layer of social proof, making the request look like a continuation of an existing business conversation rather than a cold, suspicious message. Links were also routed through a legitimate marketing service before reaching the credential-harvesting page, adding another layer of apparent legitimacy to the click path.
Defenders and executives should verify any unexpected DocuSign request by logging into DocuSign directly and checking Documents or using the Access Code feature, rather than clicking email links or buttons. Sender addresses should be checked directly rather than trusting the display name shown by an email client, particularly when a message includes what looks like an ongoing conversation thread. Organizations should also flag and treat as suspicious any messages that fail SPF, DKIM, or DMARC checks, and encourage users to report unexpected document-signing requests. Because credentials captured through these pages can be reused for follow-on attacks like business email compromise, quick reporting and verification steps are key to limiting downstream impact.
This pattern reflects known techniques such as spearphishing links, impersonation, and credential harvesting through fake web pages, documented under MITRE ATT&CK references including attack.mitre.org/techniques/T1566/002 and attack.mitre.org/techniques/T1656.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
The campaign was sent from compromised legitimate business email accounts, which helped the messages pass DMARC checks and avoid being flagged as spam.
Victims are routed through a marketing redirect service or a malicious site hosting obfuscated JavaScript, eventually landing on a fake CAPTCHA and a Gmail or Google Workspace lookalike page that captures their credentials.
Attackers pasted in a legitimate-looking thread between multiple companies to make the phishing email appear more credible and trustworthy.
According to the findings, stolen credentials were intended for follow-on attacks such as business email compromise scams or resale on marketplaces.
You get an email: “BIYH-QPVSW-3617 is ready for your review” with a big blue “Review Document” button. Looks like DocuSign, right? In a real campaign, this came from a compromised Japanese business account, not DocuSign. The link ran through a GetResponse tracking URL, then dropped victims on a fake CAPTCHA and a Gmail-style login page to steal their Google Workspace credentials. Another version says, “Please Docusign this document: Share transfer & Subscription Agreement_062024.docx Copy.docx_PM5235627.pdf” and pastes a whole prior thread. The giveaway? That weird multi-extension filename and a DocuSign email that suddenly wants your Gmail password. Here’s the move: if a DocuSign email is unexpected, don’t touch the button. Open DocuSign in your browser yourself and check for the document there.

Russia’s FSB claims Ukrainian intelligence used a Telegram dating chatbot to deceive and psychologically pressure young Russians into sharing locations,…

This weekly roundup describes multiple real-world campaigns where attackers trick people using familiar brands and “verification” prompts to steal credentials…

A Russian-linked group allegedly stole sensitive contact data from the Netherlands National Police after getting access to an employee’s email account. The…

This threat trend report describes multiple real-world APT campaigns that rely on social engineering (job offers, fake recruiters, code reviews, and…

Researchers report an active phishing-as-a-service operation, Forg365, that targets Microsoft 365 users with document/payment-themed lures and techniques that…

Amazon says North Korea-linked actors compromised widely used npm packages (including debug and chalk) by tricking a trusted maintainer into signing in through…