Fake DocuSign, Gitcode Sites Spread NetSupport RAT via Multi-Stage PowerShell Attack
Threat hunters are alerting to a new campaign that employs
deceptive websites to trick unsuspecting users into executing
malicious PowerShell scripts on their machines and infect them with
the NetSupport RAT malware. The DomainTools Investigations (DTI)
team said it identified "malicious multi-stage downloader
Powershell scripts" hosted on lure websites that masquerade as
Gitcode and DocuSign. "
Read more https://thehackernews.com/2025/06/fake-docusign-gitcode-sites-spread.html