Threat reportPhishingTL-2026-3167
Legitimate-Service Phishing (Living Off Trusted Services): ~10% of Threat Emails Abuse Trusted Platforms Such as DocuSign, QuickBooks, Adobe and Dropbox
Legitimate-Service Phishing (Living Off Trusted Services) (TL-2026-3167), also tracked as Living Off Trusted Services, is a high-severity phishing campaign, first published 2026-10-09. It has no confirmed attribution, affects DocuSign DocuSign eSignature notifications (abused), maps to 15 MITRE ATT&CK techniques (T1059.005, T1204.001, T1204.002), and is covered by 9 detection rules and 14 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 15MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 14Indicators of compromise
Key facts for TL-2026-3167
- Threat ID
- TL-2026-3167
- Also known as
- Living Off Trusted Services, LOTS phishing, Legitimate-service phishing
- Severity
- HIGH
- Status
- ACTIVE
- Category
- PHISHING
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- finance, professional-services, small-and-medium-business, enterprise
- Target regions
- Global, North America
- Detection rules
- 9
- Indicators of compromise
- 14
Malware and tooling in Legitimate-Service Phishing (Living Off Trusted Services)
Malware and tooling: AnyDesk, Smash!, AnyDesk, Atera, MeshAgent, ScreenConnect, SimpleHelp, Zoho ManageEngine UEMSAgent
How Legitimate-Service Phishing (Living Off Trusted Services) works
KnowBe4 Threat Lab reports that about 53,000 of 544,000 analyzed threat emails (June-August 2026, ~10%) were sent through legitimate platforms (LOTS). Abused services include DocuSign, QuickBooks, Google Drive, Adobe, SharePoint and Dropbox, and payloads include AiTM credential harvesting, OAuth device code phishing and RMM tool deployment (ScreenConnect, AnyDesk, Atera).
Living Off Trusted Services (LOTS) phishing, also called legitimate-service phishing, abuses the notification features of genuine SaaS platforms so that the lure email originates from the platform's own infrastructure. KnowBe4 Threat Lab analyzed 544,000 threat emails between June and August 2026 and found roughly 53,000 (~10%) were LOTS emails. KnowBe4's Phishing Threat Trends Report Vol. 7 (April 2026) had put the share of phishing attacks sent through legitimate platforms at 22%; the two figures come from different datasets and methodologies and should not be compared directly. Document-share themes account for 39.2% of phishing emails overall.
DocuSign and QuickBooks together made up roughly two thirds of LOTS volume (about a third each). DocuSign volume grew steadily month over month, while QuickBooks peaked early and then declined. Adobe volume more than doubled over the three months and Dropbox volume nearly tripled. Google Drive (comment-notification variant), SharePoint (using Microsoft's URL shortener), Box, SurveyMonkey, WeTransfer, Notion and Smash were seen at lower volumes (under 5% combined for the smaller services). Observed lures include 'Payment Received - Confirmation Details', document signature or review requests, file-sharing notifications, approval workflows and time-pressured download pages.
Attackers register free-tier accounts in minutes and send genuine notification emails. Because the mail originates from the real platform, links and sender infrastructure pass SPF, DKIM and DMARC, and secure email gateways and sender allow-lists tend to trust them; redirect chains conceal malicious infrastructure until the final click. KnowBe4 identifies three compromise methods: (1) credential harvesting via fake login pages, often fronted by adversary-in-the-middle (AiTM) proxies that defeat standard MFA; (2) device code phishing, which abuses the OAuth device-authorization flow so the victim authenticates on the genuine site and hands the attacker a live session token; and (3) deployment of remote monitoring and management (RMM) tools such as ScreenConnect, AnyDesk and Atera disguised as document readers.
The RMM delivery pattern is corroborated by BlueVoyant research (reported via eSecurity Planet, summer 2026) on a DocuSign-themed phishing kit active May-July 2026. That kit shows a fake Adobe-style PDF viewer, filters by user agent, gates the download behind Cloudflare Turnstile, reports victim telemetry (public IP, browser details, timestamp, selected filename) through the Telegram Bot API, and delivers a VBS installer that requests UAC elevation, attempts to disable Windows Defender real-time monitoring and add exclusions, and installs an RMM service (MeshAgent, ScreenConnect, SimpleHelp or Zoho ManageEngine UEMSAgent), with separate macOS delivery. Later variants delivered ScreenConnect installers hosted on Dropbox. Whether this specific kit is the one KnowBe4 observed is not stated; it is cited as corroborating context only. No CVEs, named threat actors or network IOCs are published in the KnowBe4 source, so attribution is unknown.
MITRE ATT&CK techniques used in TL-2026-3167
Execution
T1059.005 Command and Scripting Interpreter: Visual Basic; T1204.001 User Execution: Malicious Link; T1204.002 User Execution: Malicious File
Command and Control
T1219 Remote Access Tools; T1219.002 Remote Access Tools: Remote Desktop Software
Credential Access
T1528 Steal Application Access Token; T1539 Steal Web Session Cookie; T1557 Adversary-in-the-Middle
Persistence
T1543.003 Create or Modify System Process: Windows Service
Lateral Movement
T1550.001 Use Alternate Authentication Material: Application Access Token
Initial Access
T1566 Phishing; T1566.002 Phishing: Spearphishing Link
Reconnaissance
T1598 Phishing for Information
Defense Evasion
defense-impairment
Affected products and versions in Legitimate-Service Phishing (Living Off Trusted Services)
- DocuSign — DocuSign eSignature notifications (abused)
- Intuit — QuickBooks invoice/payment notifications (abused)
- Adobe — Adobe document-sharing services (abused)
- Dropbox — Dropbox file sharing (abused)
- Google — Google Drive comment notifications (abused)
- Microsoft — SharePoint and Microsoft URL shortener (abused)
Remediation for Legitimate-Service Phishing (Living Off Trusted Services)
Immediate actions
- Audit and narrow secure email gateway allow-lists for high-volume SaaS notification senders such as DocuSign, QuickBooks, Adobe and Dropbox
- Alert on first-time installation of RMM tools (ScreenConnect, AnyDesk, Atera, MeshAgent, SimpleHelp, UEMSAgent) on endpoints with no MSP or IT relationship
- Report and verify unexpected invoice, payment-confirmation and e-signature requests by logging in to the platform directly rather than via email links
Workarounds
- Restrict or block the OAuth device-code grant flow (for example with conditional access) where it is not required
- Block or monitor Telegram Bot API egress from endpoints where not business-justified
Longer-term hardening
- Deploy behavior-based email security that analyzes mail-flow patterns, urgency language and sender/context mismatches rather than relying on sender reputation and SPF/DKIM/DMARC alone
- Adopt phishing-resistant MFA (FIDO2/passkeys) to counter AiTM session-token theft
- Application-control policy allowing only approved RMM tooling
- Continue security-awareness training on trusted-platform lures
Weaknesses (CWE) in Legitimate-Service Phishing (Living Off Trusted Services)
Timeline of Legitimate-Service Phishing (Living Off Trusted Services)
- KnowBe4 Phishing Threat Trends Report Vol. 7 (April 2026) reports 22% of phishing attacks sent through legitimate platforms (exact day not stated; month-start used).
- BlueVoyant-tracked DocuSign-themed phishing kit delivering RMM tools becomes active (May-July 2026 activity window; exact start day not stated).
- Start of KnowBe4 Threat Lab analysis window (June-August 2026) covering 544,000 threat emails.
- End of observed May-July 2026 activity window for the BlueVoyant-tracked DocuSign RMM kit; later variants delivered ScreenConnect installers via Dropbox.
- End of KnowBe4 analysis window; ~53,000 emails (~10%) identified as LOTS, with Dropbox volume nearly tripled and Adobe more than doubled over the three months.
- KnowBe4 Threat Lab publishes 'The Rise of Legitimate-Service Phishing' detailing platform abuse, AiTM, device code phishing and RMM deployment.
Sources cited for Legitimate-Service Phishing (Living Off Trusted Services)
- The Rise of Legitimate-Service Phishing: 1 in 10 Phishing Emails Now Comes From a Platform You Trust (KnowBe4 Threat Lab)
- BlueVoyant: DocuSign Phishing Kit RMM Analysis
- DocuSign Phishing Kit Delivers RMM Tools to Windows and macOS (eSecurity Planet)
- Stormshield CTI: Phishing campaign with RMM installation
- KnowBe4 Threat Lab blog topic: The Skeleton Key - How Attackers Weaponize Trusted RMM Tools for Backdoor Access
- ITECS: RMM Phishing - Stop Fake DocuSign Remote Access for SMBs
Detection coverage for TL-2026-3167
As of 2026-10-09, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3167 across Splunk SPL, Microsoft KQL and Sigma, covering 14 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.