fake-docusign,-gitcode-sites-spread-netsupport-rat-via-multi-stage-powershell-attack

Threat investigators are warning about a fresh campaign that utilizes fraudulent websites to deceive unwary users into running harmful PowerShell scripts on their devices, leading to an infection with the NetSupport RAT malware.
The DomainTools Investigations (DTI) team noted it discovered “harmful multi-stage downloader PowerShell scripts” located on bait websites that imitate Gitcode and DocuSign.


Leave a Reply

Your email address will not be published. Required fields are marked *

Share This