Threat reportPhishingTL-2026-3167

Legitimate-Service Phishing (Living Off Trusted Services): ~10% of Threat Emails Abuse Trusted Platforms Such as DocuSign, QuickBooks, Adobe and Dropbox

highACTIVE

Legitimate-Service Phishing (Living Off Trusted Services) (TL-2026-3167), also tracked as Living Off Trusted Services, is a high-severity phishing campaign, first published 2026-10-09. It has no confirmed attribution, affects DocuSign DocuSign eSignature notifications (abused), maps to 15 MITRE ATT&CK techniques (T1059.005, T1204.001, T1204.002), and is covered by 9 detection rules and 14 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
15MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
14Indicators of compromise

Key facts for TL-2026-3167

Threat ID
TL-2026-3167
Also known as
Living Off Trusted Services, LOTS phishing, Legitimate-service phishing
Severity
HIGH
Status
ACTIVE
Category
PHISHING
First published
Last reviewed
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
finance, professional-services, small-and-medium-business, enterprise
Target regions
Global, North America
Detection rules
9
Indicators of compromise
14

Malware and tooling in Legitimate-Service Phishing (Living Off Trusted Services)

Malware and tooling: AnyDesk, Smash!, AnyDesk, Atera, MeshAgent, ScreenConnect, SimpleHelp, Zoho ManageEngine UEMSAgent

How Legitimate-Service Phishing (Living Off Trusted Services) works

KnowBe4 Threat Lab reports that about 53,000 of 544,000 analyzed threat emails (June-August 2026, ~10%) were sent through legitimate platforms (LOTS). Abused services include DocuSign, QuickBooks, Google Drive, Adobe, SharePoint and Dropbox, and payloads include AiTM credential harvesting, OAuth device code phishing and RMM tool deployment (ScreenConnect, AnyDesk, Atera).

Living Off Trusted Services (LOTS) phishing, also called legitimate-service phishing, abuses the notification features of genuine SaaS platforms so that the lure email originates from the platform's own infrastructure. KnowBe4 Threat Lab analyzed 544,000 threat emails between June and August 2026 and found roughly 53,000 (~10%) were LOTS emails. KnowBe4's Phishing Threat Trends Report Vol. 7 (April 2026) had put the share of phishing attacks sent through legitimate platforms at 22%; the two figures come from different datasets and methodologies and should not be compared directly. Document-share themes account for 39.2% of phishing emails overall.

DocuSign and QuickBooks together made up roughly two thirds of LOTS volume (about a third each). DocuSign volume grew steadily month over month, while QuickBooks peaked early and then declined. Adobe volume more than doubled over the three months and Dropbox volume nearly tripled. Google Drive (comment-notification variant), SharePoint (using Microsoft's URL shortener), Box, SurveyMonkey, WeTransfer, Notion and Smash were seen at lower volumes (under 5% combined for the smaller services). Observed lures include 'Payment Received - Confirmation Details', document signature or review requests, file-sharing notifications, approval workflows and time-pressured download pages.

Attackers register free-tier accounts in minutes and send genuine notification emails. Because the mail originates from the real platform, links and sender infrastructure pass SPF, DKIM and DMARC, and secure email gateways and sender allow-lists tend to trust them; redirect chains conceal malicious infrastructure until the final click. KnowBe4 identifies three compromise methods: (1) credential harvesting via fake login pages, often fronted by adversary-in-the-middle (AiTM) proxies that defeat standard MFA; (2) device code phishing, which abuses the OAuth device-authorization flow so the victim authenticates on the genuine site and hands the attacker a live session token; and (3) deployment of remote monitoring and management (RMM) tools such as ScreenConnect, AnyDesk and Atera disguised as document readers.

The RMM delivery pattern is corroborated by BlueVoyant research (reported via eSecurity Planet, summer 2026) on a DocuSign-themed phishing kit active May-July 2026. That kit shows a fake Adobe-style PDF viewer, filters by user agent, gates the download behind Cloudflare Turnstile, reports victim telemetry (public IP, browser details, timestamp, selected filename) through the Telegram Bot API, and delivers a VBS installer that requests UAC elevation, attempts to disable Windows Defender real-time monitoring and add exclusions, and installs an RMM service (MeshAgent, ScreenConnect, SimpleHelp or Zoho ManageEngine UEMSAgent), with separate macOS delivery. Later variants delivered ScreenConnect installers hosted on Dropbox. Whether this specific kit is the one KnowBe4 observed is not stated; it is cited as corroborating context only. No CVEs, named threat actors or network IOCs are published in the KnowBe4 source, so attribution is unknown.

MITRE ATT&CK techniques used in TL-2026-3167

Execution

T1059.005 Command and Scripting Interpreter: Visual Basic; T1204.001 User Execution: Malicious Link; T1204.002 User Execution: Malicious File

Command and Control

T1219 Remote Access Tools; T1219.002 Remote Access Tools: Remote Desktop Software

Credential Access

T1528 Steal Application Access Token; T1539 Steal Web Session Cookie; T1557 Adversary-in-the-Middle

Persistence

T1543.003 Create or Modify System Process: Windows Service

Lateral Movement

T1550.001 Use Alternate Authentication Material: Application Access Token

Initial Access

T1566 Phishing; T1566.002 Phishing: Spearphishing Link

Reconnaissance

T1598 Phishing for Information

Defense Evasion

T1684.001 Impersonation

defense-impairment

T1685 Disable or Modify Tools

Affected products and versions in Legitimate-Service Phishing (Living Off Trusted Services)

  • DocuSign — DocuSign eSignature notifications (abused)
  • Intuit — QuickBooks invoice/payment notifications (abused)
  • Adobe — Adobe document-sharing services (abused)
  • Dropbox — Dropbox file sharing (abused)
  • Google — Google Drive comment notifications (abused)
  • Microsoft — SharePoint and Microsoft URL shortener (abused)

Remediation for Legitimate-Service Phishing (Living Off Trusted Services)

Immediate actions

  • Audit and narrow secure email gateway allow-lists for high-volume SaaS notification senders such as DocuSign, QuickBooks, Adobe and Dropbox
  • Alert on first-time installation of RMM tools (ScreenConnect, AnyDesk, Atera, MeshAgent, SimpleHelp, UEMSAgent) on endpoints with no MSP or IT relationship
  • Report and verify unexpected invoice, payment-confirmation and e-signature requests by logging in to the platform directly rather than via email links

Workarounds

  • Restrict or block the OAuth device-code grant flow (for example with conditional access) where it is not required
  • Block or monitor Telegram Bot API egress from endpoints where not business-justified

Longer-term hardening

  • Deploy behavior-based email security that analyzes mail-flow patterns, urgency language and sender/context mismatches rather than relying on sender reputation and SPF/DKIM/DMARC alone
  • Adopt phishing-resistant MFA (FIDO2/passkeys) to counter AiTM session-token theft
  • Application-control policy allowing only approved RMM tooling
  • Continue security-awareness training on trusted-platform lures

Weaknesses (CWE) in Legitimate-Service Phishing (Living Off Trusted Services)

CWE-290

Timeline of Legitimate-Service Phishing (Living Off Trusted Services)

  • KnowBe4 Phishing Threat Trends Report Vol. 7 (April 2026) reports 22% of phishing attacks sent through legitimate platforms (exact day not stated; month-start used).
  • BlueVoyant-tracked DocuSign-themed phishing kit delivering RMM tools becomes active (May-July 2026 activity window; exact start day not stated).
  • Start of KnowBe4 Threat Lab analysis window (June-August 2026) covering 544,000 threat emails.
  • End of observed May-July 2026 activity window for the BlueVoyant-tracked DocuSign RMM kit; later variants delivered ScreenConnect installers via Dropbox.
  • End of KnowBe4 analysis window; ~53,000 emails (~10%) identified as LOTS, with Dropbox volume nearly tripled and Adobe more than doubled over the three months.
  • KnowBe4 Threat Lab publishes 'The Rise of Legitimate-Service Phishing' detailing platform abuse, AiTM, device code phishing and RMM deployment.

Sources cited for Legitimate-Service Phishing (Living Off Trusted Services)

Detection coverage for TL-2026-3167

As of 2026-10-09, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3167 across Splunk SPL, Microsoft KQL and Sigma, covering 14 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
14 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats