Clicking the “Download E-Sign” button redirects the user to a page that appears to be from Docusign and requests a key to verify the e-signature and download the purported document. After entering the access key and clicking the link, a malicious Visual Basic script named “DocuSign-E-Key_Generator-ID-- Avoid clicking links and opening attachments in unsolicited emails.
- Confirm requests from senders via contact information obtained from verified and official sources.
- Users are advised to only download applications and software from official sources.
- Maintain robust and up-to-date endpoint detection tools on every endpoint.
- Consider leveraging behavior-based detection tools rather than signature-based tools.
- If you suspect an account has been compromised, change the account's password immediately and ensure MFA is enabled for all online accounts.
- Review the Don't Take the Bait! Phishing and Other Social Engineering Attacks NJCCIC product for more information on common phishing and social engineering attacks.
- Report malicious cyber activity to the NJCCIC and the FBI's IC3.
