False docusign and gitcode -websites fool victims to download malware – here is what you need to know


  • Threat actors create fake docusign and gitcode -sites
  • The websites come with fake CAPTCHA and other scam mechanisms
  • Victims are fooled to download a Trojan

Security researchers have found false gitcode and docusign sites that distribute remote access Trojan (rat) malware using the infamous clickfix method.

Experts from Domaintool’s Investigations (DTI) found “malicious multi-stage downloader Powershell scripts” who hosted spoofed sites inviting visitors to pull up Windows Run Terminal and run a script copied to their clipboard.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top