Target Industry

Indiscriminate, opportunistic targeting.

Overview

The emergence of a sophisticated malware campaign leveraging fake DocuSign and Gitcode sites has raised significant concerns in the cyber security community. Discovered in early June 2025, this campaign employs a multi-stage PowerShell attack to deliver the NetSupport remote access trojan (RAT), a tool originally designed for legitimate remote administration but now repurposed for malicious purposes. The significance of this discovery lies in the evolving tactics used by cybercriminals, which increasingly rely on social engineering and familiar interfaces to deceive users into compromising their systems. 

Impact

The potential impact of the NetSupport RAT on affected systems is significant. Organisations may face financial losses due to data breaches, operational disruptions, and reputational damage. The ability of the malware to monitor user activity and exfiltrate sensitive information poses serious risks to both individuals and businesses. \

Exploitation

The distribution of the NetSupport RAT occurs through phishing campaigns that direct users to counterfeit websites resembling DocuSign and Gitcode. Victims are often lured by emails or social media messages that prompt them to visit these fraudulent sites. Once on the site, users are tricked into executing malicious PowerShell scripts, which initiate the malware installation process. The use of clipboard poisoning and deceptive CAPTCHA prompts further enhances the effectiveness of this attack vector. 

The malware uses PowerShell scripts to download and run extra payloads. These scripts are often hidden using techniques like ROT13 encoding. The initial script is copied to the clipboard, prompting the user to paste it into the Windows Run prompt. 

Once executed, the PowerShell script connects to remote servers controlled by threat actors, downloading the NetSupport RAT. This allows threat actors to control the infected system and create persistence mechanisms to stay active after reboots.  

The NetSupport RAT captures keystrokes, takes screenshots, and monitors user activity in real-time. It communicates with command-and-control (C2) servers to receive instructions and send stolen data. It often modifies the Windows Registry to run at startup. 

Containment, Mitigations & Remediations

To mitigate the threat posed by the NetSupport RAT, organisations should implement robust security measures, including regular software updates, employee training on recognising phishing attempts, and the use of advanced threat detection systems. Additionally, endpoint protection solutions that can detect and block malicious PowerShell scripts are essential for defending against these types of threats. 

Threat Landscape

The multi-stage PowerShell attack leveraging fake DocuSign and Gitcode sites to distribute the NetSupport RAT underscores the increasing sophistication of cyber threats. By employing social engineering tactics to lure victims into executing malicious payloads, threat actors can effectively compromise systems and exfiltrate sensitive data. Organisations must remain vigilant and proactive in their cybersecurity efforts to mitigate the risks associated with such advanced persistent threats. 

Threat Group

There are several threat groups who have been seen to leverage the NetSupport RAT. Some of the threat groups are: 

  • FIN7 (Carbon Spider, ELBRUS, Sangria Tempest, GOLD NIAGARA, and Carbanak) – Russian cybercriminal group established around 2013, known for financially motivated attacks 
  • Scalet Goldfinch – emerged in June 2023, using fake browser updates to distribute malware 
  • Storm-0408 – a collective name for threat actors identified in December 2024, known for distributing malware via phishing, SEO, and malvertising campaigns. 

Further Information

Domain Tools article 

Further Threat Intelligence from Quorum Cyber

Headquarters

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

FLORIDA, USA Office

501 E Kennedy Blvd.
STE 1400
Tampa FL 33602

Ontario, Canada Office

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

Contact Us
Address

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

501 E Kennedy Blvd
STE 1400
Tampa FL 33602

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

HEADQUARTERS
Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ



FLORIDA, USA OFFICE
501 E Kennedy Blvd.
STE 1400
Tampa FL 33602


ONTARIO, CANADA OFFICE
1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7


Legal

Privacy Preference Center

Skip to content