NetSupport RAT is a Windows remote access trojan built through abuse or repurposing of the legitimate NetSupport Manager remote administration software. It is widely observed as a second-stage or follow-on payload in criminal intrusion chains and is commonly used to provide persistent remote access for hands-on-keyboard activity after initial compromise. Reported operations have used it alongside loaders and stealers including CastleLoader, HijackLoader, Matanbuchus, StealC, CastleStealer, Remcos, and other commodity malware families.
Observed delivery chains frequently rely on social engineering rather than exploitation. NetSupport RAT has repeatedly appeared in ClickFix campaigns that impersonate CAPTCHA, browser verification, update, meeting, or support workflows and trick victims into pasting attacker-supplied commands into Windows Run or PowerShell. It has also been delivered through phishing emails, trojanized installers, malicious JavaScript downloaders, DLL sideloading, and as a payload retrieved by multi-stage loaders such as CastleLoader and Hancitor.
Once installed, NetSupport RAT provides operators with remote control of the infected Windows host and is used as a durable access mechanism across campaigns. Associated reporting ties its use to persistence, interactive post-compromise operations, data theft, and in some cases lateral movement. Campaigns delivering NetSupport RAT have targeted enterprises broadly, including technology-sector victims, and it has also appeared in opportunistic web-based and malvertising-style social-engineering operations affecting general users. In several 2025–2026 campaigns, it was one of the more common payloads observed in ClickFix-related activity and in CastleLoader clusters such as Urutyka, Garrigin, and Noidret.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
A legitimately signed NetSupport Manager v14.12 binary -- bearing a valid GlobalSign EV code-signing certificate issued to NETSUPPORT LTD -- is being weaponized as a Remote Access Trojan across two active delivery chains.
20 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
На компьютерах под управлением Windows атакующие пытались установить NetSupport RAT. Этот троян злоупотребляет легитимным инструментом удаленного администрирования NetSupport Manager и предоставляет своим операторам доступ к зараженной системе.
Similar to other RMM tools, NetSupport manager has been exploited to be used maliciously, to a point of a malicious by-product of the platform being created - aptly named NetSupport RAT.
Similar to other RMM tools, NetSupport manager has been exploited to be used maliciously, to a point of a malicious by-product of the platform being created - aptly named NetSupport RAT.
The group has been linked to past campaigns that delivered dangerous tools including NetSupport RAT, Remcos RAT, StealC, and Sectop RAT.
The TA571 campaign contained at least two different command lines running different PowerShell scripts, one leading to DarkGate via a downloaded HTA-file that ran another PowerShell script and one leading to NetSupport RAT via a downloaded ZIP file.
Scarlet Goldfinch is a cluster of activity that Red Canary first observed in June 2023. This threat deceives users into downloading a file masquerading as a browser update, which starts a chain of activity eventually leading to the installation of NetSupport Manager. NetSupport Manager is an RMM tool that provides the adversary remote control over a system.
22 distinct techniques documented for this family, organized by ATT&CK tactic.
Opening the shortcut then ran a hidden PowerShell command, which quietly pulled and ran the next stage in memory.
As a result, users unknowingly execute a malicious PowerShell command, enabling malicious loaders to be launched at the next stage on the device.
While observing the JS file that was downloaded, we noticed that the code is obfuscated by a generic JS obfuscator (Obfuscate.io).
Opening the shortcut then ran a hidden PowerShell command, which quietly pulled and ran the next stage in memory.
CastleLoader queries its C2 via a get_tasks command. Tasks return encrypted payloads... By replicating the get_tasks request... we were able to decrypt the HTTP response and confirm the payload manifest and downstream C2s...
In some cases, malicious components may establish persistence on the system, attempt to weaken the operation of security software and enable the download of additional malicious files.
573 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
183 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A persistent remote access payload repeatedly delivered by CastleLoader across the observed campaigns.
A remote access trojan referenced as one of the payloads or tools associated with CastleLoader campaign infrastructure.
A remote administration tool abused as malware in ClickFix campaigns to provide unauthorized remote access to affected systems.
A persistent remote access payload repeatedly deployed as a final-stage capability across the CastleLoader campaign cluster.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.