DocuSign-Themed M365 AiTM Phish Uses Redirect Chain

The Hacker News · Medium sophistication
Last updated September 7, 2026

The recap describes a real Microsoft 365 phishing campaign using DocuSign-themed emails that push victims through multiple redirects to a fake sign-in page. The goal is to steal session tokens (so attackers can log in even if a password changes) and also perform “device code” style sign-in abuse. The article also notes a newer trick where QR codes made of plain text can still appear even when email images are blocked.

Key findings

  • Attackers used a QR code made from text so it still renders even when email images are blocked.
  • A Microsoft 365 adversary-in-the-middle (AiTM) phishing kit (“Knight Office”) used DocuSign-themed lures to send victims to fake landing pages designed to steal session tokens.
  • The described phishing flow included multiple redirects, including via Monday and a compromised Joomla website, before victims reached the phishing page.
  • The recap also mentions other active exploitation activity (browsers, routers, e-commerce platforms), but the most simulation-ready social-engineering detail is the DocuSign-themed M365 phishing lure and redirect workflow.

Who’s being targeted

  • Commonly targeted roles: All employees, Executives, Finance, HR, Sales, IT helpdesk (to recognize token-theft/AiTM reports).
  • Affected industries: Cross-industry (Microsoft 365 users).
  • Attack channels: email, website.
  • Impersonated: DocuSign.

Awareness takeaways

  • Treat DocuSign-style “review/sign” emails as high-risk and verify the destination before signing in.
  • Be suspicious of sign-in flows that bounce through multiple redirects, close the browser and re-open the site from a known bookmark.
  • Blocking email images alone is not a complete defense, attackers can still present scannable QR content without images.

Red flags to watch for

  • Multiple unexpected redirects before the sign-in page (including through unrelated services).
  • Sign-in page is not the normal Microsoft/DocuSign domain.
  • Email may still show scannable QR content even with images blocked.
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You get an email: “DocuSign: Please review and sign.” Looks normal, right? This one isn’t. You click the link or scan the QR, and your browser bounces: first to Monday.com, then a random Joomla site, then finally a Microsoft 365 sign‑in that looks real. This is a Microsoft 365 adversary‑in‑the‑middle kit called Knight Office. When you sign in here, it doesn’t just steal your password, it steals your session token so they can log in as you even after you change it. If a DocuSign email makes you sign in to Microsoft and you see weird redirects, stop. Close the tab and open DocuSign or M365 from your own bookmark instead.

Similar attacks

Hotel Wi‑Fi Lures and Entra Vishing Hit Users

Hotel Wi‑Fi Lures and Entra Vishing Hit Users

The article reports real-world social engineering operations, including a hotel Wi‑Fi campaign that pushed fake updates and device-code phishing to steal Microsoft 365 access. It also describes an alleged Microsoft Entra vishing campaign tied to data theft claims at Brinks Home, reinforcing the…

August 7, 2026
Fake SSO + MFA Push Used in Real Breaches

Fake SSO + MFA Push Used in Real Breaches

This weekly roundup includes two real social-engineering-driven incidents. Attackers used social engineering to access Apollo Global Management’s cloud platforms and steal sensitive personal data, and separately attempted a ShinyHunters phishing attack against ReliaQuest using a fake SSO login page…

August 28, 2026
Fake Cloudflare CAPTCHA Tricks Users Into Running Code

Fake Cloudflare CAPTCHA Tricks Users Into Running Code

A campaign dubbed “TerminalFix” uses compromised websites to display fake Cloudflare CAPTCHA checks that instruct visitors to copy and run a PowerShell command. The goal is to get a user to run attacker-provided commands themselves, which can lead to persistent access and deeper intrusion into the…

August 31, 2026
Fake Claude & Perplexity Lures Push Malware

Fake Claude & Perplexity Lures Push Malware

Sophos reports real incidents where attackers impersonated well-known AI brands (especially Claude) to trick people into installing malware. The lures included polished fake installer pages that instruct victims to copy/paste commands, and browser extensions that look legitimate via high ratings…

August 21, 2026
Job Offer & Doc-Link Phishing Drive Real Breaches

Job Offer & Doc-Link Phishing Drive Real Breaches

This weekly threat bulletin describes real incidents where attackers used human manipulation to break in, including social engineering at Levi Strauss and a Microsoft 365 credential-theft phish at defense supplier IEH. It also highlights a Lazarus-linked campaign using fake job offers and…

August 17, 2026
Hotel WiFi Scam Pushes Fake Updates and Malware

Hotel WiFi Scam Pushes Fake Updates and Malware

A Russia-linked threat group compromised hotel WiFi captive portals to redirect guests to fake “verification” pages. Victims were pushed toward either copying commands into a terminal to install malware or entering Microsoft credentials on spoofed login pages that added an attacker-controlled…

August 7, 2026