# Legitimate-Service Phishing (Living Off Trusted Services): ~10% of Threat Emails Abuse Trusted Platforms Such as DocuSign, QuickBooks, Adobe and Dropbox

> KnowBe4 Threat Lab reports that about 53,000 of 544,000 analyzed threat emails (June-August 2026, ~10%) were sent through legitimate platforms (LOTS). Abused services include DocuSign, QuickBooks, Google Drive, Adobe, SharePoint and Dropbox, and payloads include AiTM credential harvesting, OAuth device code phishing and RMM tool deployment (ScreenConnect, AnyDesk, Atera).

- **Published:** 2026-10-09T00:00:00Z
- **Last reviewed:** 2026-10-09T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-3167
- **ID:** TL-2026-3167
- **Severity:** HIGH
- **Category:** PHISHING
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 14 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Living Off Trusted Services (LOTS) phishing, also called legitimate-service phishing, abuses the notification features of genuine SaaS platforms so that the lure email originates from the platform's own infrastructure. KnowBe4 Threat Lab analyzed 544,000 threat emails between June and August 2026 and found roughly 53,000 (~10%) were LOTS emails. KnowBe4's Phishing Threat Trends Report Vol. 7 (April 2026) had put the share of phishing attacks sent through legitimate platforms at 22%; the two figures come from different datasets and methodologies and should not be compared directly. Document-share themes account for 39.2% of phishing emails overall.

DocuSign and QuickBooks together made up roughly two thirds of LOTS volume (about a third each). DocuSign volume grew steadily month over month, while QuickBooks peaked early and then declined. Adobe volume more than doubled over the three months and Dropbox volume nearly tripled. Google Drive (comment-notification variant), SharePoint (using Microsoft's URL shortener), Box, SurveyMonkey, WeTransfer, Notion and Smash were seen at lower volumes (under 5% combined for the smaller services). Observed lures include 'Payment Received - Confirmation Details', document signature or review requests, file-sharing notifications, approval workflows and time-pressured download pages.

Attackers register free-tier accounts in minutes and send genuine notification emails. Because the mail originates from the real platform, links and sender infrastructure pass SPF, DKIM and DMARC, and secure email gateways and sender allow-lists tend to trust them; redirect chains conceal malicious infrastructure until the final click. KnowBe4 identifies three compromise methods: (1) credential harvesting via fake login pages, often fronted by adversary-in-the-middle (AiTM) proxies that defeat standard MFA; (2) device code phishing, which abuses the OAuth device-authorization flow so the victim authenticates on the genuine site and hands the attacker a live session token; and (3) deployment of remote monitoring and management (RMM) tools such as ScreenConnect, AnyDesk and Atera disguised as document readers.

The RMM delivery pattern is corroborated by BlueVoyant research (reported via eSecurity Planet, summer 2026) on a DocuSign-themed phishing kit active May-July 2026. That kit shows a fake Adobe-style PDF viewer, filters by user agent, gates the download behind Cloudflare Turnstile, reports victim telemetry (public IP, browser details, timestamp, selected filename) through the Telegram Bot API, and delivers a VBS installer that requests UAC elevation, attempts to disable Windows Defender real-time monitoring and add exclusions, and installs an RMM service (MeshAgent, ScreenConnect, SimpleHelp or Zoho ManageEngine UEMSAgent), with separate macOS delivery. Later variants delivered ScreenConnect installers hosted on Dropbox. Whether this specific kit is the one KnowBe4 observed is not stated; it is cited as corroborating context only. No CVEs, named threat actors or network IOCs are published in the KnowBe4 source, so attribution is unknown.

## MITRE ATT&CK

- T1598 Phishing for Information
- T1566 Phishing
- T1566.002 Phishing: Spearphishing Link
- T1204.001 User Execution: Malicious Link
- T1204.002 User Execution: Malicious File
- T1059.005 Command and Scripting Interpreter: Visual Basic
- T1543.003 Create or Modify System Process: Windows Service
- T1685 Disable or Modify Tools
- T1684.001 Impersonation
- T1557 Adversary-in-the-Middle
- T1528 Steal Application Access Token
- T1539 Steal Web Session Cookie
- T1550.001 Use Alternate Authentication Material: Application Access Token
- T1219 Remote Access Tools
- T1219.002 Remote Access Tools: Remote Desktop Software

## Sources

- [The Rise of Legitimate-Service Phishing: 1 in 10 Phishing Emails Now Comes From a Platform You Trust (KnowBe4 Threat Lab)](https://blog.knowbe4.com/the-rise-of-legitimate-service-phishing-1-in-10-phishing-emails-now-comes-from-a-platform-you-trust)
- [BlueVoyant: DocuSign Phishing Kit RMM Analysis](https://www.bluevoyant.com/blog/docusign-phishing-kit-rmm-analysis)
- [DocuSign Phishing Kit Delivers RMM Tools to Windows and macOS (eSecurity Planet)](https://www.esecurityplanet.com/threats/docusign-phishing-kit-delivers-rmm-tools-to-windows-and-macos/)
- [Stormshield CTI: Phishing campaign with RMM installation](https://www.stormshield.com/news/cti-phishing-campaign-rmm-installation/)
- [KnowBe4 Threat Lab blog topic: The Skeleton Key - How Attackers Weaponize Trusted RMM Tools for Backdoor Access](https://blog.knowbe4.com/topic/knowbe4-threat-lab)
- [ITECS: RMM Phishing - Stop Fake DocuSign Remote Access for SMBs](https://itecsonline.com/post/rmm-phishing-stop-fake-docusign-remote-access-for-smbs)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-3167
