← Back to Pulse Feed
PULSE DETAIL
PULSE NAME
Malicious Scripts Delivered via Fake Gitcode and Docusign Pages
A new cyber campaign is using fake websites impersonating Gitcode and DocuSign to trick users into running malicious PowerShell scripts, ultimately infecting systems with NetSupport RAT malware. Researchers found that these deceptive sites prompt victims to copy and execute PowerShell commands, which then download additional scripts from external servers.
Indicators of Compromise (15 / 69 total)