NetSupport Manager RAT is a maliciously repurposed deployment of the legitimate NetSupport Manager remote access tool used by attackers to obtain unauthorized remote control of infected Windows systems. The provided content links it to multiple delivery chains and campaigns, including SmartApeSG/ClickFix activity and MSIX-based malware distribution. In the SmartApeSG chain, victims are socially engineered via fake verification or CAPTCHA pages to execute malicious scripts; an initial unidentified RAT communicates over TCP 443 using encoded non-SSL traffic, then downloads a second-stage NetSupport Manager RAT package. Observed installation artifacts include C:\ProgramData\processor.vbs (SHA256 469bac8e10f50263e8ff0806e6ba126bb4cc660799129a8653eab3f8ec7201e5), C:\ProgramData\token.bat (SHA256 9c7eda2c4d3aaa8746495741bef57a07de180f0409409faf0f91658e88ba33f5), and C:\ProgramData\setup.cab (SHA256 7ba5481c873bb3081442561f749f590badd72ef249fddfe993e30b28dc0c2112), with contents extracted to C:\ProgramData\UpdateInstaller; token.bat establishes persistence and deletes staging files after installation. Reported SmartApeSG-related infrastructure includes hiddenplanetlab[.]top URLs, silverharvestnetwork[.]com/check, 178.156.165[.]82, 178.156.173[.]194, initial RAT C2 89.110.110[.]119:443, and NetSupport RAT C2 185.163.47[.]217:443. Separate traffic analysis identified suspected NetSupport Manager RAT communications with 45.131.214[.]85 over TCP 443 beginning 2026-02-28 19:55 UTC from infected host 10.2.28[.]88. The content also associates NetSupport Manager RAT with FIN7/Sangria Tempest MSIX campaigns in which malicious MSIX packages used StartingScriptWrapper.ps1 and embedded PowerShell with process injection to execute POWERTRASH and Carbanak, which then delivered NetSupport Manager RAT as a follow-on payload. Those MSIX campaigns were distributed via malvertising/SEO poisoning and impersonated legitimate software such as Grammarly, Microsoft Teams, Notion, and Zoom, affecting organizations across multiple industries. Additional reporting cited a ClickFix campaign abusing the finger command to retrieve remote commands and, after checking for analysis tools, delivering a PDF-spoofing ZIP archive that extracted a NetSupport Manager RAT package. One noted artifact in FIN7-linked samples was binary metadata referencing "Crosstec Corporation" instead of "NetSupport Corporation."
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
When victims open these MSIX packages, the StartingScriptWrapper.ps1 component launches embedded PowerShell scripts that employ process injection to execute POWERTRASH and Carbanak malware, which subsequently deliver NetSupport Manager RAT.
My previous in-depth diary about a SmartApeSG (ZPHP, HANEYMANEY) was in November 2025, when I saw NetSupport Manager RAT.
29 distinct techniques documented for this family, organized by ATT&CK tactic.
Victims are typically lured through malicious advertising or SEO poisoning campaigns, believing they are downloading legitimate software such as Grammarly, Microsoft Teams, Notion, or Zoom.
MITRE ATT&CK Mapping Technique ID Context Obtain Capabilities: Tool T1588.002 Legitimate NetSupport Manager repurposed as RAT
A batch script called token.bat handles the extraction and installation, while a VBScript file called processor.vbs triggers the batch script.
Defenders are advised to monitor for unusual PowerShell execution tied to browser events, as this is a clear sign of the ClickFix technique being abused.
A batch script called token.bat handles the extraction and installation... Together, these components install the NetSupport RAT and configure it to run automatically whenever the system restarts.
The page copies a PowerShell command to the victim's clipboard and instructs them to press Win+R, Ctrl+V, Enter. Standard ClickFix technique -- the victim executes the malware themselves, bypassing email attachment scanning, download warnings, and Mark-of-the-Web protections.
That loader uses variable indirection to construct the string iex : sv o ie # $o = 'ie' .((gv o).Value + 'X') # invoke ('ie' + 'X') = iex
MITRE ATT&CK Mapping Technique ID Context Obfuscated Files: Software Packing T1027.002 PyInstaller packing; XOR encryption with StagerKey16Bytes
a dual-lure NetSupport Manager RAT operation... A CS2 "Iridia Cheats" lure at iridiacheats.dev ... A "Polymarket Smart Money Scanner" whale-tracker lure at polymarketscanner.dev
Registers as "Windows Update Assistant" (v10.0.19045.3448, "Microsoft Corporation") — T1036.005
After the NetSupport RAT is installed and made persistent on the host, the scripts used to set it up are deleted automatically, removing traces of the initial compromise.
Several signature hits for NetSupport Manager RAT from 45.131.214[.]85 over TCP port 443. The activity started on 2026-02-28 at 19:55 UTC.
MITRE ATT&CK Mapping Technique ID Context Application Layer Protocol: Web T1071.001 HTTP gateway ( /fakeurl.htm , /testpage.htm )
Once the script runs, it silently reaches out to attacker-controlled servers and pulls down the first stage of the infection... The script then contacts attacker infrastructure to fetch a ZIP archive containing the initial RAT package from a remote server.
83 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Remote access trojan activity identified via network traffic, with connections from the infected host to 45.131.214[.]85 over TCP/443.
A legitimate remote access tool repurposed by attackers as a persistent remote access trojan. In this campaign it is delivered as the second-stage payload, installed via CAB/batch/VBScript components, configured for persistence, and used to take unauthorized control of infected Windows hosts.
Remote access trojan delivered as a malicious NetSupport Manager package after an initial unidentified RAT infection; the package is installed via scripts and made persistent on the infected Windows host.
Remote access trojan previously observed in SmartApeSG campaign activity before the campaign more consistently shifted to Remcos RAT.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.