
Fake DocuSign Flow Tricks Users Into RMM Installs
Researchers found a DocuSign lookalike phishing workflow that guides people through a realistic “document viewing” experience and then convinces them to…
Cofense reports real phishing campaigns where attackers trick employees into installing legitimate remote access tools (like GoTo, Datto RMM, SimpleHelp, and ConnectWise). After the first tool is installed, it contacts a command-and-control server that directs it to download additional remote tools and utilities to help attackers keep access without being noticed. The approach is often used to create and sell “initial access” into corporate networks to other criminals.
These campaigns begin with a phishing email that directs the recipient to a lookalike website. Instead of delivering traditional malware, the site prompts the user to download and run a legitimate remote access tool, such as GoTo, SimpleHelp, ConnectWise, or Datto RMM. Once installed, the tool contacts command-and-control infrastructure, which then instructs it to pull down additional payloads, sometimes another remote access tool entirely. This multi-stage chain gives attackers persistent, low-visibility access to the victim machine.
Each pretext leaned on a routine workplace action to make the request feel normal:
Because the payloads are legitimate, widely used administrative tools rather than obviously malicious files, they are less likely to trigger suspicion from users and can blend in with normal IT activity.
Employees across HR, finance, legal, executive assistant, and IT helpdesk roles are all named as target audiences, reflecting how broadly these pretexts can be aimed. Awareness efforts should reinforce that legitimate remote access and monitoring tools can be abused for attacker persistence, not just custom malware. Encourage staff to update software only through official channels, to be cautious of any emailed link that results in an executable download, and to report unexpected remote-access prompts or installs immediately. Recognizing that a single suspicious install can be just the first stage of a longer intrusion, one that may later fetch more tools or payloads, helps employees understand why quick reporting matters even if nothing seems obviously wrong yet.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
It starts with a phishing email that links to a fake page which installs a legitimate remote access tool. Once installed, that tool contacts a command-and-control server that instructs it to download additional payloads or remote tools.
Cofense observed attackers abusing legitimate tools including GoTo, Datto RMM, SimpleHelp, and ConnectWise RAT as first-stage installers.
Legitimate tools are trusted by employees and security controls, which helps attackers gain and maintain persistence in enterprise environments while reducing suspicion.
The findings note that attackers may monetize this persistent access by selling it as an initial access broker to other criminals.
You get an email: “You need to access a file using Adobe Cloud.” You click, and a page says your Adobe PDF viewer is out of date. Here’s the trick: that “update” link quietly installs a legit remote tool like GoTo or SimpleHelp. Then it calls home to download more tools, so someone can stay on your machine and even sell access to it. Aha moment: real invites and documents don’t make you download an .exe just to read them. If an “Adobe update” or “personalized invitation” wants you to run an installer from a link in an email, that’s your red flag. If any email link tells you to install or update software to view a file or invitation, stop and report it to IT Security before you click anything else.

Researchers found a DocuSign lookalike phishing workflow that guides people through a realistic “document viewing” experience and then convinces them to…

Researchers report an active phishing-as-a-service operation, Forg365, that targets Microsoft 365 users with document/payment-themed lures and techniques that…

Researchers reported a real phishing campaign (“Operation BlueDash”) that tricks users with a “secure document” lure and routes them to a fake Microsoft Store…

German and international law enforcement disrupted the infrastructure behind “Kratos,” a phishing-as-a-service kit used at scale to steal Microsoft account…

Cofense observed a real phishing campaign impersonating Google Ads Sync Accounts (MMC) with a fake “maintenance/system upgrade” notice. The email pressures…

Cofense reports that attackers target finance teams with phishing emails designed to look like normal invoices, contracts, and payment notices, not urgent “act…