Fake DocuSign and Gitcode sites are tricking victims into downloading malware – here’s what you need to know




  • Threat actors are creating fake DocuSign and Gitcode websites
  • The sites come with fake CAPTCHA and other scam mechanisms
  • Victims are tricked into downloading a Trojan

Security researchers have found fake Gitcode and DocuSign websites distributing remote access trojan (RAT) malware using the infamous ClickFix method.

Experts from DomainTools Investigations (DTI) found “malicious multi-stage downloader Powershell scripts” hosted on spoofed websites inviting visitors to pull up the Windows Run terminal and run a script copied into their clipboard.

https://cdn.mos.cms.futurecdn.net/zjafjw6AeTXTuuLetiazgC.jpg



Source link

Latest articles

spot_imgspot_img

Related articles

spot_imgspot_img