NetSupport RAT is the malicious repurposing of NetSupport Manager/NetSupport Client, a legitimate Windows remote-support product, to provide unauthorized interactive remote access to compromised endpoints. Threat actors deploy the signed legitimate client with its supporting configuration and runtime components, allowing them to control hosts, install follow-on malware, and potentially move laterally within affected environments. It has been observed in campaigns associated with SocGholish/FakeUpdates, BattleRoyal, UAC-0050, and other cybercriminal activity, including operations targeting Ukrainian organizations and social-engineering campaigns targeting conference attendees. Delivery chains have included phishing and social-media lures, malicious document and counterfeit installer workflows, ClickFix prompts that induce PowerShell execution, fake browser updates delivered from compromised websites, and large-scale email campaigns. Windows-focused installations have established persistence through scheduled tasks or user-level startup configuration and, in some cases, removed temporary artifacts and command-history traces to hinder forensic investigation.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Additionally, the .URL files involved exploited CVE-2023-36025, a vulnerability in Windows SmartScreen. ... The vulnerability could allow an actor to bypass the SmartScreen defenses if a user clicked on a specially crafted .URL file or a hyperlink pointing to a .URL file.
Mandiant has also identified the exploitation of Microsoft Exchange vulnerabilities, including ProxyShell and ProxyLogon, as another access point leveraged by UNC2596 likely as early as August 2021.
Mandiant has also identified the exploitation of Microsoft Exchange vulnerabilities, including ProxyShell and ProxyLogon, as another access point leveraged by UNC2596 likely as early as August 2021.
A legitimately signed NetSupport Manager v14.12 binary -- bearing a valid GlobalSign EV code-signing certificate issued to NETSUPPORT LTD -- is being weaponized as a Remote Access Trojan across two active delivery chains.
24 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Beginning in early January 2025, eSentire Threat Response Unit (TRU) observed an increase in the number of incidents involving the NetSupport Remote Access Trojan (RAT).
Beginning in early January 2025, eSentire Threat Response Unit (TRU) observed an increase in the number of incidents involving the NetSupport Remote Access Trojan (RAT).
Beginning in early January 2025, eSentire Threat Response Unit (TRU) observed an increase in the number of incidents involving the NetSupport Remote Access Trojan (RAT).
Beginning in early January 2025, eSentire Threat Response Unit (TRU) observed an increase in the number of incidents involving the NetSupport Remote Access Trojan (RAT).
Since the beginning of 2025, UAC-0050 switched to NetSupport Manager for its malware operations in both January and February.
Current samples of Font_Chrome.exe are file downloaders. They retrieve follow-up malware that installs a NetSupport Manager remote access tool (RAT).
30 distinct techniques documented for this family, organized by ATT&CK tactic.
Une page partagée ChatGPT légitime affiche un message indiquant un trafic élevé et redirige vers le site malveillant openai-backup.one.
Étape 1 – Loader PowerShell initial : récupère et exécute un script depuis brmconfig.com, masque la fenêtre console, effectue des vérifications système.
video.mp4 ... contient un payload PowerShell chiffré ... déchiffré par XOR à clé répétée puis décompressé via GZip.
Malgré son extension, video.mp4 contient un payload PowerShell chiffré dans une boîte UUID MP4 personnalisée, déchiffré par XOR à clé répétée puis décompressé via GZip.
A single uuid box occupies 99.95% of the file, containing an XOR key and compressed PowerShell... It is a convincing shell designed solely to pass automated file-type inspections while masking the transport of a large script.
The video is valid as a media file, but it also holds an encrypted and compressed PowerShell bundle in a custom data area.
Déchiffrement par XOR à clé répétée puis décompression GZip.
A second payload disguised as a DocSend installer delivered the appropriate macOS or Windows payload.
T1036.001 — Masquerading: Invalid Code Signature (Defense Evasion); app.EXe est signé numériquement par NetSupport Ltd.
Collecte d’informations : IP publique, localisation, FAI, fuseau horaire.
Collecte d’informations : nom de machine, nom d’utilisateur, version Windows, architecture CPU, statut administrateur.
Données transmises vers un chat Telegram contrôlé par l’attaquant.
Ces données sont exfiltrées vers un chat Telegram contrôlé par l’attaquant.
848 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A legitimate NetSupport remote-support client repurposed and deployed as a remote-access trojan through a ClickFix/PowerShell infection chain. The campaign collects host, user, OS, CPU, administrator-status, public-IP, geolocation, ISP, and time-zone data, exfiltrates it to attacker-controlled Telegram, and supports capabilities including screen capture.
Outil d'administration à distance NetSupport Client détourné dans cette campagne via une chaîne ClickFix/PowerShell. Le payload final permet le contrôle distant de l'hôte compromis; la chaîne collecte aussi des informations système et les transmet à un canal Telegram contrôlé par l'attaquant.
A Windows remote access trojan delivered as part of the campaign, providing attacker access to infected systems.
A remote access trojan delivered to Windows users through a counterfeit installer as part of a post-conference social-engineering campaign.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.