PULSE NAME
How Threat Actors Exploit Human Trust: A Breakdown of the 'Prove You Are Human' Malware Scheme
WHITE AlienVault 2025-06-05 Modified: 2025-07-05
73
IOCs
HIGH VOLUME
A malicious campaign exploits user trust through deceptive websites, including spoofed Gitcodes and fake Docusign verification pages. Victims are tricked into running malicious PowerShell scripts on their Windows machines, leading to the installation of NetSupport RAT. The multi-stage attack uses clipboard poisoning and fake CAPTCHAs to deliver the malware. The campaign involves multiple domains, uses ROT13 encoding, and creates persistent infections. Similar techniques were observed in other spoofed content, including Okta and popular media apps. The attack capitalizes on user familiarity with common online interactions, emphasizing the need for vigilance and skepticism in online activities.
Indicators of Compromise (3 / 73 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 96f78187e8fc777efc3740740db4fba5 2025-06-05
FileHash-MD5 9dabf38bd7d2b88ef196ad531202d045 2025-06-05
FileHash-MD5 a384eb33be4f98c4df33ac1b99d1c417 2025-06-05