{"id":417596,"date":"2026-09-23T18:50:37","date_gmt":"2026-09-23T18:50:37","guid":{"rendered":"https:\/\/malwaretips.com\/blogs\/?p=417596"},"modified":"2026-09-23T18:50:37","modified_gmt":"2026-09-23T18:50:37","slug":"docusign-invites-blob-phishing-browser","status":"publish","type":"post","link":"https:\/\/malwaretips.com\/blogs\/docusign-invites-blob-phishing-browser\/","title":{"rendered":"DocuSign Invites Build Phishing Pages in Your Browser"},"content":{"rendered":"<p>The email says a document is ready for signature. A calendar invitation is attached, the button opens a Microsoft address, and familiar DocuSign and Adobe branding appears along the way.<\/p><div id=\"mwtad992238113\" class=\"gas_fallback-ad_309684--placement_406659\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3957935887\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<p>Each screen seems to confirm the one before it. By the time a login form appears, the browser has already passed through services most workers recognize.<\/p>\n<p>The trust is real. The document and the sign-in page are not.<\/p><div id=\"mwtad2089159182\" class=\"gas_fallback-ad_381396-ad_309685-placement_406667\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"1471373341\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<figure><img loading=\"lazy\" decoding=\"async\" width=\"1200\" height=\"675\" src=\"data:image\/gif;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw==\" class=\"wp-image-417597 lazyload\" alt=\"DocuSign-themed email and calendar invite leading to a document review button\" title=\"\" sizes=\"auto, (max-width: 1200px) 100vw, 1200px\" data-src=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/docusign-invites-blob-phishing-browser-1-final.png\" data-srcset=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/docusign-invites-blob-phishing-browser-1-final.png 1200w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/docusign-invites-blob-phishing-browser-1-final-300x169.png 300w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/docusign-invites-blob-phishing-browser-1-final-1024x576.png 1024w\"><\/figure>\n<div id=\"mwtad2387992263\" class=\"gas_fallback-ad_309746-ad_309685-placement_406660\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"4456629336\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>Overview<\/h2>\n<h3>The phishing email arrives with a calendar invitation<\/h3>\n<p>Barracuda researchers analyzed a multi-layered credential-phishing campaign that begins with a DocuSign-themed email. The message says a document needs review or signature and includes a calendar invitation to make the request look scheduled and businesslike.<\/p>\n<p>A calendar file can place the event beside real meetings and generate reminders after the original email has left the inbox. That persistence gives the lure more than one chance to be clicked.<\/p>\n<p>The invitation is not proof that a DocuSign envelope exists. It is another message format that the sender can create and attach.<\/p><div id=\"mwtad2026257805\" class=\"gas_fallback-ad_309686-ad_309685-placement_406668\" style=\"margin-top: 50px;margin-right: 10px;margin-bottom: 50px;margin-left: 10px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"6935453015\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<h3>Legitimate Microsoft services are used as stepping stones<\/h3>\n<p><a href=\"https:\/\/blog.barracuda.com\/2026\/09\/08\/browser-in-the-browser-phishing-docusign-adobe-microsoft\" target=\"_blank\" rel=\"noopener\">Barracuda&#8217;s campaign analysis<\/a> found that the link first pointed to a legitimate Microsoft OAuth endpoint. A crafted redirect then moved the browser through Microsoft Teams before loading an external resource from attacker-controlled infrastructure.<\/p>\n<p>Seeing microsoft.com in the early address can reassure a cautious recipient. The campaign exploits that moment of recognition, but a legitimate redirect service does not approve the final destination.<\/p>\n<p>The chain also mixes DocuSign, Adobe, and Microsoft visual cues. Instead of impersonating one company consistently, it borrows trust from several brands at different steps.<\/p><div id=\"mwtad2099749577\" class=\"gas_fallback-ad_381401-ad_309685-placement_406669\" style=\"margin-top: 50px;margin-right: 10px;margin-bottom: 50px;margin-left: 10px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"5315249587\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<h3>The final phishing page is assembled inside the browser<\/h3>\n<p>The external resource uses browser features, including a blob URL, service workers, and an embedded frame, to construct the fake login experience. A blob address begins with <code>blob:<\/code> and represents data created locally for that browser session rather than a conventional public webpage.<\/p>\n<p>That does not make blob URLs malicious by themselves. Legitimate websites use them for files and media. In this campaign, the technique helped separate the visible phishing page from the ordinary domain trail and supported a workflow controlled by the attacker&#8217;s infrastructure.<\/p>\n<ul>\n<li>The message imitates a DocuSign signature request.<\/li>\n<li>An attached calendar invite adds urgency and reminders.<\/li>\n<li>The first click uses a real Microsoft OAuth address.<\/li>\n<li>A crafted redirect moves the browser through Microsoft Teams.<\/li>\n<li>Attacker-controlled content is loaded from an external delivery network.<\/li>\n<li>The browser creates a blob URL for the final phishing interface.<\/li>\n<li>DocuSign, Adobe, and Microsoft branding are combined to reinforce trust.<\/li>\n<li>The final form collects credentials rather than opening a real document.<\/li>\n<\/ul>\n<figure><img loading=\"lazy\" decoding=\"async\" width=\"1200\" height=\"675\" src=\"data:image\/gif;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw==\" class=\"wp-image-417598 lazyload\" alt=\"Redirect chain moving from a Microsoft OAuth page to an external blob URL\" title=\"\" sizes=\"auto, (max-width: 1200px) 100vw, 1200px\" data-src=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/docusign-invites-blob-phishing-browser-2-final.png\" data-srcset=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/docusign-invites-blob-phishing-browser-2-final.png 1200w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/docusign-invites-blob-phishing-browser-2-final-300x169.png 300w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/docusign-invites-blob-phishing-browser-2-final-1024x576.png 1024w\"><\/figure>\n<div id=\"mwtad2281551501\" class=\"gas_fallback-ad_309747-ad_309685-placement_406661\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"9589536513\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>Why the Redirect Chain Feels Safe<\/h2>\n<h3>Every brand is plausible in a document workflow<\/h3>\n<div id=\"mwtad1703287889\" class=\"gas_fallback-ad_381404-ad_309685-placement_406670\" style=\"margin-top: 50px;margin-right: 10px;margin-bottom: 50px;margin-left: 10px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"8735619847\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><p>A contract may genuinely be sent through DocuSign, previewed as a PDF, and opened by someone using Microsoft 365. The presence of multiple familiar brands therefore does not look unusual at first.<\/p>\n<p>The scam uses that familiarity as a relay. The recipient recognizes one logo, then another, and assumes the companies are validating each other. They are not.<\/p>\n<h3>The first domain is not the final destination<\/h3>\n<p>Security advice often tells people to inspect a link before clicking. That remains useful, but redirect abuse shows why the check must continue after the browser opens. A real Microsoft endpoint can accept parameters that send a user elsewhere.<\/p>\n<div id=\"mwtad172929699\" class=\"mwtadp5 mwtadentity-placement\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"https:\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\"\r\n     crossorigin=\"anonymous\"><\/script>\r\n<ins class=\"adsbygoogle\"\r\n     style=\"display:block; text-align:center;\"\r\n     data-ad-layout=\"in-article\"\r\n     data-ad-format=\"fluid\"\r\n     data-ad-client=\"ca-pub-7750719144850257\"\r\n     data-ad-slot=\"8560433799\"><\/ins>\r\n<script>\r\n     (adsbygoogle = window.adsbygoogle || []).push({});\r\n<\/script><\/div><p>The important question is where the login credentials will actually be submitted. If the address changes unexpectedly or the page appears under a blob URL, stop and reopen the service from a known bookmark.<\/p>\n<h3>The page exists only for that browser session<\/h3>\n<p>A conventional phishing site can be scanned by following its URL. A page assembled inside the browser is more difficult to investigate in the same way because the visible blob address is local and temporary.<\/p>\n<p>That temporary nature can also confuse victims. Copying the address into another browser may not reproduce the page, which can make the incident feel like a harmless glitch rather than a credential theft attempt.<\/p>\n<div id=\"mwtad2210559656\" class=\"gas_fallback-ad_309748-ad_309685-placement_406662\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3906789406\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>Company and Checkout Checks<\/h2>\n<h3>The sender name is not the signing company<\/h3>\n<div id=\"mwtad2571196406\" class=\"mwtadp6 mwtadentity-placement\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"https:\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\"\r\n     crossorigin=\"anonymous\"><\/script>\r\n<ins class=\"adsbygoogle\"\r\n     style=\"display:block; text-align:center;\"\r\n     data-ad-layout=\"in-article\"\r\n     data-ad-format=\"fluid\"\r\n     data-ad-client=\"ca-pub-7750719144850257\"\r\n     data-ad-slot=\"4034304343\"><\/ins>\r\n<script>\r\n     (adsbygoogle = window.adsbygoogle || []).push({});\r\n<\/script><\/div><p>An email can display \u201cDocuSign,\u201d a colleague&#8217;s name, or a vendor name while originating from an unrelated account. Expand the full sender address and compare the supposed document with a transaction you actually expect.<\/p>\n<p>Real signature requests should identify the sending organization and document context. A vague \u201cconfidential document\u201d with no verifiable business reference deserves an independent call to the sender.<\/p>\n<h3>The calendar address is not a contract record<\/h3>\n<p>Anyone can create a calendar event and attach an invitation. Check the organizer, attendees, event description, and links. An unexpected event should not be accepted merely because it appears in the calendar application.<\/p>\n<p>Rejecting or deleting the event may not remove a related email rule or account compromise, so investigate how it arrived if the sender appears to be an internal account.<\/p>\n<h3>Real support will not ask for the captured password<\/h3>\n<p>DocuSign, Adobe, and Microsoft do not need a user&#8217;s Microsoft password typed into a page assembled by an unrelated external resource. If a login is required, open the official service directly and check for the document there.<\/p>\n<p>Support contacts listed inside the suspicious message are part of the same unverified chain. Use known company directories or official websites instead.<\/p>\n<h3>The credential form is the checkout<\/h3>\n<p>No money needs to change hands on the phishing page. The valuable item is the username, password, session approval, or multifactor code. Submitting the form completes the attacker&#8217;s transaction.<\/p>\n<p>Once captured, a work account can expose email, documents, contacts, cloud applications, and trusted relationships. The attacker may then send convincing signature requests from the real mailbox.<\/p>\n<div id=\"mwtad2741382617\" class=\"gas_fallback-ad_318930-ad_309685-placement_406663\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3818335085\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>How the DocuSign Blob Phishing Scam Works<\/h2>\n<h3>Step 1: A fake signature request enters the inbox<\/h3>\n<p>The recipient receives an email styled as a DocuSign notification. It claims that a contract, invoice, or confidential document needs attention and presents a clear review button.<\/p>\n<p>The subject and wording are designed for workplaces where digital signatures are routine. The victim is encouraged to act as part of normal business rather than evaluate an unusual opportunity.<\/p>\n<h3>Step 2: A calendar invite creates another prompt<\/h3>\n<p>The attached invitation can add the supposed signing deadline to the calendar. A reminder may appear later, even if the recipient ignored the original email.<\/p>\n<p>This creates persistence without sending repeated messages. It also makes the request look connected to a scheduled event.<\/p>\n<h3>Step 3: The click opens a legitimate Microsoft OAuth endpoint<\/h3>\n<p>The link begins on real Microsoft infrastructure. A user who checks only the first hostname may believe the destination has been validated.<\/p>\n<p>OAuth endpoints legitimately handle authorization and redirection. The attacker abuses that expected behavior by supplying a crafted destination in the chain.<\/p>\n<h3>Step 4: Microsoft Teams loads an external resource<\/h3>\n<p>The browser is moved through a Teams-related path that reaches content controlled by the attacker. Each legitimate service acts as a visual trust marker, even though it does not own the final form.<\/p>\n<p>Redirects can happen quickly. A person watching the page rather than the address bar may never notice the transition.<\/p>\n<h3>Step 5: Browser code builds the phishing page<\/h3>\n<p>Code from the external source creates the final experience inside the browser. Service-worker behavior and an embedded frame help manage the page, while a blob URL becomes visible as the local address.<\/p>\n<p>The page can display copied Microsoft, Adobe, or DocuSign design elements without being hosted on any of those companies&#8217; normal sign-in domains.<\/p>\n<p>The address bar may now be difficult to interpret. A long temporary identifier can distract from the missing official domain, while the page itself stays visually simple and familiar. The user sees a logo, an email field, and a blue button, so the browser machinery behind it fades into the background.<\/p>\n<h3>Step 6: The form asks for Microsoft credentials<\/h3>\n<p>The victim sees a login prompt that appears to stand between them and the document. The form may ask for an email first, then a password, and possibly a verification code.<\/p>\n<p>Entered information goes to the attacker&#8217;s workflow. An error or loading screen may then appear to make the failed document preview seem ordinary.<\/p>\n<h3>Step 7: The stolen account becomes the next delivery channel<\/h3>\n<p>If the credentials and authentication controls are enough, the attacker can enter the mailbox, search for valuable conversations, and send new lures to coworkers or customers.<\/p>\n<p>A message from a genuinely compromised account is harder to dismiss than the first external email. The scam can grow through existing business relationships.<\/p>\n<p>The attacker can also read recent conversations before replying. That context may reveal project names, invoices, or colleagues who routinely exchange documents, allowing the next lure to sound far more specific than the original campaign email.<\/p>\n<figure><img loading=\"lazy\" decoding=\"async\" width=\"1200\" height=\"675\" src=\"data:image\/gif;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw==\" class=\"wp-image-417599 lazyload\" alt=\"Fake Microsoft sign-in form displayed from a temporary blob URL in the browser\" title=\"\" sizes=\"auto, (max-width: 1200px) 100vw, 1200px\" data-src=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/docusign-invites-blob-phishing-browser-3-final.png\" data-srcset=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/docusign-invites-blob-phishing-browser-3-final.png 1200w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/docusign-invites-blob-phishing-browser-3-final-300x169.png 300w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/docusign-invites-blob-phishing-browser-3-final-1024x576.png 1024w\"><\/figure>\n<div id=\"mwtad598063308\" class=\"gas_fallback-ad_381388-ad_309685-placement_406705\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3191649120\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>How to Verify a Real Document Request<\/h2>\n<p>Do not verify the document by replying to the suspicious email. Contact the supposed sender through a known phone number, existing conversation, or company directory. Ask for the document title and why it was sent.<\/p>\n<p>Then open DocuSign, Adobe Acrobat Sign, or Microsoft 365 from a saved bookmark or by typing the official address yourself. A genuine request tied to your account should be visible through the service&#8217;s own dashboard or notification history.<\/p>\n<ul>\n<li>Check the full sender and calendar-organizer addresses.<\/li>\n<li>Compare the request with work you are actually expecting.<\/li>\n<li>Hover over or inspect links before opening them.<\/li>\n<li>Watch every address change, not just the first domain.<\/li>\n<li>Stop if a sign-in page appears under a <code>blob:<\/code> address.<\/li>\n<li>Open the signing service independently in a new browser window.<\/li>\n<li>Do not enter a password after a chain of unexplained redirects.<\/li>\n<li>Report suspicious invitations so other recipients can be warned.<\/li>\n<\/ul>\n<p>A blob URL alone is not proof of fraud, because legitimate applications use this browser feature. In the context of an unexpected signing request and a Microsoft credential form, it is a strong reason to stop and verify the workflow independently.<\/p>\n<p>Organizations can make that verification easier by giving staff one clear way to report signing requests. Mail filters should preserve the original message and calendar attachment for analysis, while security teams review redirects, OAuth activity, and sign-ins that follow the click.<\/p>\n<div id=\"mwtad1789876696\" class=\"gas_fallback-ad_381392-ad_309685-placement_406664\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"2944237110\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>What to Do if You Have Fallen Victim to This Scam<\/h2>\n<ol>\n<li><strong>Use a clean device for recovery.<\/strong> Close the phishing page and switch to a device you trust, especially if you downloaded anything or approved browser permissions.<\/li>\n<li><strong>Change the Microsoft password immediately.<\/strong> Go directly to the official account portal. Use a new, unique password that has not been used on another service.<\/li>\n<li><strong>Revoke active sessions.<\/strong> Sign out other sessions and review recent sign-ins, locations, devices, and applications. Report unfamiliar activity.<\/li>\n<li><strong>Inspect authentication methods.<\/strong> Remove unknown phone numbers, authenticator registrations, passkeys, recovery addresses, app passwords, and trusted devices.<\/li>\n<li><strong>Check the mailbox for persistence.<\/strong> Look for forwarding rules, hidden inbox rules, deleted warnings, changed signatures, and messages sent without your knowledge.<\/li>\n<li><strong>Notify the real security team.<\/strong> For a work account, report the email, calendar file, URLs, time of submission, and any multifactor approval. Fast reporting can protect coworkers.<\/li>\n<li><strong>Run a Malwarebytes scan.<\/strong> Credential phishing can occur without malware, but a scan can detect malicious downloads or extensions added during the chain. Keep the browser and operating system updated.<\/li>\n<li><strong>Use AdGuard to block known malicious pages.<\/strong> Filtering can stop many phishing and ad-driven domains from loading. It is an additional layer, not a substitute for checking the final login domain.<\/li>\n<li><strong>Contact affected services.<\/strong> If the stolen password was reused, change it everywhere. Alert banks or payment services if financial documents or sessions were accessible.<\/li>\n<li><strong>Preserve evidence.<\/strong> Save the original message as a file if company policy allows, along with the calendar invite, sender headers, screenshots, and browser history. Do not forward the live lure to coworkers.<\/li>\n<\/ol>\n<p>Be suspicious of follow-up calls claiming to be Microsoft, DocuSign, or the company&#8217;s fraud team. Attackers can use the submitted email address and incident details to make a second request sound informed.<\/p>\n<div id=\"mwtad2271499930\" class=\"gas_fallback-ad_381392-ad_309685-placement_406665\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"2944237110\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>Frequently Asked Questions<\/h2>\n<h3>Is this DocuSign calendar phishing campaign confirmed?<\/h3>\n<p>Yes. Barracuda Research analyzed the email, calendar invitation, redirect chain, browser behavior, and final credential-phishing workflow.<\/p>\n<h3>Does the campaign mean DocuSign was breached?<\/h3>\n<p>No such conclusion follows from the report. The attackers impersonated DocuSign and abused trust in several brands; that is different from proving those companies were compromised.<\/p>\n<h3>Why does the link begin with a real Microsoft domain?<\/h3>\n<p>The campaign abuses legitimate redirect behavior. A trustworthy first hop does not guarantee that the final destination or credential form is trustworthy.<\/p>\n<h3>Are all blob URLs dangerous?<\/h3>\n<p>No. Blob URLs are a normal browser feature used by legitimate sites. The danger here comes from how the phishing chain uses one to display an unexpected login page.<\/p>\n<h3>Can a calendar invitation steal my password by itself?<\/h3>\n<p>The invitation mainly delivers and repeats the lure. Credential theft occurs when the user follows the link and submits information to the fake page.<\/p>\n<h3>How can I safely open a genuine DocuSign request?<\/h3>\n<p>Verify the sender separately, then open the official DocuSign site or app directly and check the account&#8217;s envelope history instead of following the email chain.<\/p>\n<h2>The Bottom Line<\/h2>\n<p>This DocuSign blob phishing campaign is a confirmed, carefully layered credential trap. It uses a calendar invite and legitimate Microsoft services as stepping stones, then builds the fake login inside the browser.<\/p>\n<p>Familiar logos and a real first domain do not validate the final form. When a document request takes an unexpected route, open the signing service directly and confirm the request with the sender before entering a password.<\/p>\n<div id=\"mwtad308596331\" class=\"gas_fallback-ad_176819-ad_309685-placement_406666\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"8386082122\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>The email says a document is ready for signature. A calendar invitation is attached, the button opens a Microsoft address, and familiar DocuSign and Adobe branding appears along the way. Each screen seems to confirm &#8230; <\/p>\n<p class=\"read-more-container\"><a title=\"DocuSign Invites Build Phishing Pages in Your Browser\" class=\"read-more button\" href=\"https:\/\/malwaretips.com\/blogs\/docusign-invites-blob-phishing-browser\/#more-417596\" aria-label=\"Read more about DocuSign Invites Build Phishing Pages in Your Browser\">Read more<\/a><\/p>\n","protected":false},"author":51,"featured_media":417597,"comment_status":"open","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[49],"tags":[],"class_list":["post-417596","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-scam-reports","masonry-post","generate-columns","tablet-grid-50","mobile-grid-100","grid-parent","grid-50","resize-featured-image"],"_links":{"self":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/417596","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/users\/51"}],"replies":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/comments?post=417596"}],"version-history":[{"count":2,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/417596\/revisions"}],"predecessor-version":[{"id":417813,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/417596\/revisions\/417813"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/media\/417597"}],"wp:attachment":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/media?parent=417596"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/categories?post=417596"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/tags?post=417596"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}