PULSE NAME
How Threat Actors Exploit Human Trust: A Breakdown of the 'Prove You Are Human' Malware Scheme
WHITE AlienVault 2025-06-05 Modified: 2025-07-05
73
IOCs
HIGH VOLUME
A malicious campaign exploits user trust through deceptive websites, including spoofed Gitcodes and fake Docusign verification pages. Victims are tricked into running malicious PowerShell scripts on their Windows machines, leading to the installation of NetSupport RAT. The multi-stage attack uses clipboard poisoning and fake CAPTCHAs to deliver the malware. The campaign involves multiple domains, uses ROT13 encoding, and creates persistent infections. Similar techniques were observed in other spoofed content, including Okta and popular media apps. The attack capitalizes on user familiarity with common online interactions, emphasizing the need for vigilance and skepticism in online activities.
Indicators of Compromise (3 / 73 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA1 8e7e3bbcf8d51243462dca4d03af1f0ceabb54e6 2025-06-05
FileHash-SHA1 8f0b8261a1eff925a39ca117099bc8b0317c941b 2025-06-05
FileHash-SHA1 94d786cd03f8dff56e4f97f5817894c482d5f6fa 2025-06-05