False Docusign and Gitcode sites encourage victims to download malware – here is what you need to know


  • Threat actors create false Docusign and Gitcode websites
  • The sites are delivered with a false Captcha and other scam mechanisms
  • The victims are deceived to download a Trojen

Security researchers have found false Gitcode and Docusign websites distributing remote malware (RAT) using the infamous clickfix method.

Experts from Domaintools (DTI) investigations have found that “PowerShell scripts of several malware downloaders” hosted on usurped websites inviting visitors to withdraw the Windows execution terminal and execute a copied script in their clipboard.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top