
Forg365 Phishing Kit Steals Microsoft 365 Sessions
Researchers report an active phishing-as-a-service operation, Forg365, that targets Microsoft 365 users with document/payment-themed lures and techniques that…
Researchers found a DocuSign lookalike phishing workflow that guides people through a realistic “document viewing” experience and then convinces them to download legitimate remote access tools. Instead of classic malware, the attackers install trusted IT administration software (RMM) to keep long-term access on both Windows and macOS while blending into normal IT activity.
This campaign starts with a phishing page designed to look like a DocuSign document ready for review. Victims are told to click an "Open in Acrobat" style button, which loads a convincing fake viewer complete with a progress bar, document preview, and navigation panel. Before the download button activates, victims must pass a Cloudflare Turnstile verification check. This step adds a layer of legitimacy and also helps the attackers filter out automated security scanners from real targets.
Once verification passes, the victim is offered a download. Rather than delivering traditional malware, the file installs legitimate remote monitoring and management (RMM) software such as MeshAgent, ScreenConnect, SimpleHelp, or Zoho ManageEngine UEMSAgent. The campaign has shifted delivery methods over time, initially using a Visual Basic Script installer before moving to ScreenConnect installers hosted on Dropbox.
The workflow succeeds because it closely imitates a routine business process: signing or reviewing a document through DocuSign. Each stage, from the loading screen to the verification check, reinforces a sense of legitimacy. By delivering real administrative tools instead of custom malware, the attackers gain a major advantage: security teams that watch for known malicious files may overlook RMM software that IT departments already use for support and management tasks.
The kit also uses user-agent filtering and staged validation checks, which suggests the operators are deliberately screening out researchers and automated tools while focusing on genuine victims. Telemetry such as IP addresses, browser details, and filenames is reportedly sent to the attackers through the Telegram Bot API once a victim reaches the download stage.
Organizations can reduce risk from this type of attack by training employees to verify unexpected e-signature requests through a separate, trusted communication channel before downloading anything. IT and security teams should also monitor for RMM installations that were not requested or approved, since legitimate tools can still be misused for persistent access. Detection should extend beyond known malware signatures to include suspicious scripting behavior, such as wscript.exe launching PowerShell or attempts to disable Microsoft Defender, since these actions often accompany this kind of installation.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
It is a phishing workflow that mimics a DocuSign document viewing experience, complete with a fake Adobe Acrobat style interface, to convince victims to download software that turns out to be legitimate remote monitoring and management (RMM) tools.
Because it installs legitimate IT administration tools such as MeshAgent, ScreenConnect, SimpleHelp, and Zoho ManageEngine UEMSAgent instead of traditional malware, allowing the activity to blend into normal IT operations.
Red flags include a document workflow that asks you to download or run software, an unusual verification step like Cloudflare Turnstile before a download, and installer scripts that request admin or UAC elevation.
Train employees to verify unexpected e-signature requests through a trusted channel, monitor for unapproved RMM installs, and detect suspicious scripting activity such as attempts to disable Microsoft Defender.
You get a DocuSign link, click it, and a super-polished PDF viewer pops up with an “Open in Acrobat” button. Looks normal, right? Behind the scenes, this fake DocuSign flow walks you through a Cloudflare Turnstile check, then tells you to download a “viewer” that’s actually MeshAgent or ScreenConnect remote access software. Here’s the tell: real DocuSign never makes you install software, run a script, or approve an admin prompt just to view a document, especially not something hosted on Dropbox. If a DocuSign link ever asks you to download or install anything, stop and go to docusign.com directly or call the sender to confirm before you click.

Researchers report an active phishing-as-a-service operation, Forg365, that targets Microsoft 365 users with document/payment-themed lures and techniques that…

This weekly roundup describes multiple real-world campaigns where attackers trick people using familiar brands and “verification” prompts to steal credentials…

Okta says it gained an inside look at “Work Panel,” a polished SaaS-style dashboard that helps voice-phishing (vishing) crews rapidly set up fake login sites…

German and international law enforcement disrupted the infrastructure behind “Kratos,” a phishing-as-a-service kit used at scale to steal Microsoft account…

ClickFix is a fast-growing social engineering tactic that gets people to run malware themselves by pasting a command into Windows Run or macOS Terminal.…

Researchers found a live Microsoft 365 phishing server accidentally left open with directory listing enabled, exposing phishing configs, stolen credential…