Phish Impersonating DocuSign

Published on: 
April 30, 2024

195 domains registered and used for credential phishing

We spotted 195 domains registered and used for credential phishing pulled from a phish impersonating DocuSign using a click thru URL obfuscator.

The initial domain was qi6kd[.]com which showed a google workspace login, off a DocuSign-impersonating email with a link to a malicious site.

Related Content

SecuritySnacks
Cybersecurity Reading List - Week of 2026-08-17
Learn More
SecuritySnacks
SecuritySnack - Account Farmers and Sellers
Explore how account farmers exploit lax signup friction to inflate metrics and sell verified accounts. Discover key IOCs and mitigation strategies.
Learn More
SecuritySnacks
Scarcity Scams
Discover how scarcity scams exploit government service bottlenecks to commit wire fraud and identity theft. Learn the tactics behind fake fast-track portals.
Learn More