From Fake DocuSign to ScreenConnect: Attack Blocked
Attackers sent fake DocuSign emails to Florida healthcare workers, pretending to be real screening forms. The emails tricked people into downloading a fake Adobe installer that secretly installed ScreenConnect, a program that lets attackers take over their computers remotely.
- Report priority
- Medium
- Targets
- Healthcare
How it works
- Attackers sent fake emails that looked like official DocuSign messages.
- They tricked Florida healthcare workers into clicking a link that led to a fake Cloudflare verification page.
- The page asked them to download a ZIP file containing a malicious HTA file.
- When opened, the file used Base64-encoded VBScript to mimic an Adobe installer.
- It then used Windows tools like mshta.exe and msiexec.exe to silently install ScreenConnect, a program that gives attackers remote access to the victim's computer.
- The attack was designed to bypass security checks by using legitimate Windows tools and modifying Microsoft Defender's registry settings.
What to do
If you work in Florida healthcare and got an email from DocuSign about screening forms, check if you clicked any links or downloaded files from it. If you did, watch for unusual activity on your computer, like unexpected programs installing or your screen being controlled by someone else.
If you clicked a link or downloaded a file from the email, immediately scan your computer with updated antivirus software. Check your installed programs for anything unfamiliar, especially ScreenConnect or ConnectWise ScreenConnect. If you see anything suspicious, uninstall it and contact your IT department or cybersecurity support for further assistance. If you did not interact with the email, no further action is needed.
Technical details
An employee at a Florida healthcare facility received an email that appeared to be from DocuSign, asking them to complete a screening form. The email contained a link to a fake Cloudflare verification page. When the employee clicked the link, they were prompted to download a ZIP file. Inside the ZIP file was an HTA file disguised as an Adobe installer. When opened, the file silently installed ScreenConnect, allowing attackers to remotely access the employee's computer.
A phishing campaign abused trusted brands like DocuSign and Cloudflare to deliver malicious ScreenConnect remote access clients. Attackers hosted fake verification workflows on Cloudflare Pages to appear legitimate, then lured victims with healthcare-related lures from Florida. The payload was a ZIP archive containing a Base64-encoded HTA file that used VBScript to bypass security controls, including modifying Microsoft Defender SmartScreen registry entries and escalating privileges via UAC.
The attack leveraged native Windows tools like mshta.exe, curl.exe, and msiexec.exe to silently install ScreenConnect, granting unauthorized remote access. The campaign was detected and blocked before payload delivery, classified as Zero Hour Fraudulent under OTX-6aa374470d15d76b861b2f68.