EVALUSION is a designation for a malicious NetSupport Manager campaign cluster identified through shared NetSupport licensing and configuration artifacts, overlapping delivery infrastructure, and common tradecraft. The cluster has used multiple NetSupport licensee names and mixed versions of the legitimate remote-administration software. Its operations relied on ClickFix social engineering, in which victims are persuaded to execute commands through the Windows Run dialog, followed by PowerShell- or MSI-based staged loaders that install and launch NetSupport Manager for remote access. Observed loaders decode embedded payloads, write components to concealed directories, and establish Startup-folder persistence. A newer loader variant removes Windows Run-dialog history artifacts, providing a defense-evasion measure. EVALUSION-associated infrastructure has been distributed across multiple hosting regions; this infrastructure distribution does not establish the operator's country of origin. The EVALUSION label is a campaign-cluster identifier and shared NetSupport license artifacts alone are insufficient to establish that every occurrence using those artifacts belongs to one distinct threat actor.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as prior activity associated with reuse of the same malicious NetSupport Manager license file; it is not attributed to the analyzed campaign.
NetSupport Manager abuse cluster delivering a NetSupport client via ClickFix social engineering (victim runs commands in Windows Run prompt). Uses a recurring PowerShell/JSON loader (and variants including RunMRU deletion) to drop NetSupport, establish persistence via Startup folder shortcut, and execute the client (e.g., client32.exe). Also observed using curl->batch loaders per assessment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.