FSHGDREE32/SGI is a threat cluster associated with malicious deployment of NetSupport Manager through socially engineered initial-access chains. The cluster was identified as one of several distinct NetSupport-related campaigns active in 2025 and is distinguished by NetSupport license artifacts tied to the names FSHGDREE32 and SGI. Its operations relied on convincing victims to execute commands through the Windows Run dialog as part of ClickFix-style lures, reflecting a broader shift away from earlier fake-update delivery patterns. The cluster used PowerShell-based loaders to retrieve and execute follow-on content that unpacked and launched NetSupport Manager on compromised systems. Observed loader behavior included decoding embedded base64 content, parsing JSON-structured payload data, writing multiple components to hidden directories, validating required NetSupport files, and launching the NetSupport client. Persistence was established through the Startup folder. A newer loader variant removed RunMRU artifacts to reduce forensic evidence of user-executed Run prompt commands. A less common delivery path used MSI packages executed via msiexec as a living-off-the-land mechanism, followed by an encoded multi-stage PowerShell chain. Operationally, the cluster was linked by shared configuration artifacts, including a common NetSupport secret value and related license metadata. Two associated license identities were observed: FSHGDREE32, using an older NetSupport client version, and SGI, also tied to an older client version and a revoked certificate. Infrastructure patterns indicated concentration in Eastern Europe and overlap with bulletproof-hosting characteristics. The cluster’s tradecraft is consistent with remote-access-focused post-compromise activity centered on covert deployment, persistence, and defense evasion rather than ransomware or destructive operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.