NetSupport RAT is a malicious remote-access trojan derived from abuse of the legitimate NetSupport Manager remote administration product. It is used to provide operators with interactive access to compromised Windows systems and has been observed as a second-stage payload in multiple criminal intrusion chains. Reported capabilities include remote control of infected hosts, file exfiltration, loading of additional payloads, and enabling sustained hands-on-keyboard activity associated with persistence and follow-on compromise.
The malware is frequently delivered through social-engineering-driven initial access chains rather than direct exploitation. It has been repeatedly observed in ClickFix campaigns that trick users into executing attacker-supplied commands through trusted Windows interfaces and utilities. It has also been delivered through phishing email chains using redirect-heavy links and JavaScript downloaders, through DLL sideloading in multi-stage infections, and as a follow-on payload from other malware delivery ecosystems including SocGholish/FakeUpdates and Hancitor. Broader reporting also associates NetSupport RAT use with abuse of remote monitoring and management tooling by financially motivated threat actors, including campaigns linked to FIN7.
Operationally, NetSupport RAT is used to establish covert remote access on victim endpoints, often as part of intrusion sequences that also involve loaders, stealers, or ransomware. In observed campaigns it has targeted enterprise users and organizations in sectors including technology, and it has appeared in wider opportunistic web-based malware distribution affecting schools, healthcare, legal, media, retail, nonprofits, and real estate. Its recurring role as a post-compromise access mechanism makes it a common bridge between initial social engineering and later-stage credential theft, data theft, additional malware deployment, or ransomware activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
A legitimately signed NetSupport Manager v14.12 binary -- bearing a valid GlobalSign EV code-signing certificate issued to NETSUPPORT LTD -- is being weaponized as a Remote Access Trojan across two active delivery chains.
20 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
На компьютерах под управлением Windows атакующие пытались установить NetSupport RAT. Этот троян злоупотребляет легитимным инструментом удаленного администрирования NetSupport Manager и предоставляет своим операторам доступ к зараженной системе.
Similar to other RMM tools, NetSupport manager has been exploited to be used maliciously, to a point of a malicious by-product of the platform being created - aptly named NetSupport RAT.
Similar to other RMM tools, NetSupport manager has been exploited to be used maliciously, to a point of a malicious by-product of the platform being created - aptly named NetSupport RAT.
The group has been linked to past campaigns that delivered dangerous tools including NetSupport RAT, Remcos RAT, StealC, and Sectop RAT.
The TA571 campaign contained at least two different command lines running different PowerShell scripts, one leading to DarkGate via a downloaded HTA-file that ran another PowerShell script and one leading to NetSupport RAT via a downloaded ZIP file.
Scarlet Goldfinch is a cluster of activity that Red Canary first observed in June 2023. This threat deceives users into downloading a file masquerading as a browser update, which starts a chain of activity eventually leading to the installation of NetSupport Manager. NetSupport Manager is an RMM tool that provides the adversary remote control over a system.
28 distinct techniques documented for this family, organized by ATT&CK tactic.
The exe file uses a few techniques for persistence: Scheduled tasks Startup Menu file saving Registry Key
Opening the shortcut then ran a hidden PowerShell command, which quietly pulled and ran the next stage in memory.
Opening the shortcut then ran a hidden PowerShell command, which quietly pulled and ran the next stage in memory.
The exe file uses a few techniques for persistence: Scheduled tasks Startup Menu file saving Registry Key
While observing the JS file that was downloaded, we noticed that the code is obfuscated by a generic JS obfuscator (Obfuscate.io).
Opening the shortcut then ran a hidden PowerShell command, which quietly pulled and ran the next stage in memory.
We can also see that all of the files were retrieved from the same domain... and how it uses “start-bitstransfer” to retrieve them from the C2 server to the client(victim’s machine).
C2: 216.126.237[.]122:443 Confirmed via JA3 TLS fingerprinting and malware config extraction
Opening the shortcut then ran a hidden PowerShell command, which quietly pulled and ran the next stage in memory.
563 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
178 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
RAT observé comme payload livré via ClickFix.
A remote access payload mentioned as part of the ClickFix delivery rotation.
NetSupport RAT3
A remote access trojan or remote access tool used as a ClickFix-delivered payload in the campaigns discussed.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.