NetSupport Manager RAT is the malicious use of NetSupport Manager, a legitimate Windows remote-administration product, to provide unauthorized remote control of compromised systems. Threat actors deploy repackaged or otherwise malicious instances as follow-on payloads after initial compromise, enabling persistent post-compromise access. Observed delivery chains include phishing documents, ClickFix social-engineering lures, malicious MSIX installers distributed through malvertising and SEO poisoning, and payloads delivered by other malware such as Hancitor, POWERTRASH, and Carbanak. Campaigns have used NetSupport Manager RAT against Windows systems in opportunistic, multi-industry operations as well as in ransomware-associated intrusions. It has been linked in reporting to FIN7/Sangria Tempest activity, Cuba ransomware-associated REF9019 intrusions, and SmartApeSG campaigns. Malicious installations have been configured to start automatically and may remove installation artifacts after deployment. Network behavior has included external IP geolocation checks and command-and-control communications characteristic of NetSupport Manager.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"Our sample is the NetSupportManager RAT"; it was named ra.exe and written and executed by the previously exploited Exchange IIS worker process.
When victims open these MSIX packages, the StartingScriptWrapper.ps1 component launches embedded PowerShell scripts that employ process injection to execute POWERTRASH and Carbanak malware, which subsequently deliver NetSupport Manager RAT.
My previous in-depth diary about a SmartApeSG (ZPHP, HANEYMANEY) was in November 2025, when I saw NetSupport Manager RAT.
27 distinct techniques documented for this family, organized by ATT&CK tactic.
A batch script called token.bat handles the extraction and installation, while a VBScript file called processor.vbs triggers the batch script.
Defenders are advised to monitor for unusual PowerShell execution tied to browser events, as this is a clear sign of the ClickFix technique being abused.
A batch script called token.bat handles the extraction and installation... Together, these components install the NetSupport RAT and configure it to run automatically whenever the system restarts.
These are rather generic maldocs which contain obfuscated VB/Macros which retrieve a specially-crafted .PNG image file.
The page copies a PowerShell command to the victim's clipboard and instructs them to press Win+R, Ctrl+V, Enter. Standard ClickFix technique -- the victim executes the malware themselves, bypassing email attachment scanning, download warnings, and Mark-of-the-Web protections.
MITRE ATT&CK Mapping Technique ID Context Obfuscated Files: Software Packing T1027.002 PyInstaller packing; XOR encryption with StagerKey16Bytes
a dual-lure NetSupport Manager RAT operation... A CS2 "Iridia Cheats" lure at iridiacheats.dev ... A "Polymarket Smart Money Scanner" whale-tracker lure at polymarketscanner.dev
s’est fait passer pour le VP Marketing de CoinDesk... faux DocSend ... forge un certificat pour www.virustotal.com ... fichiers DockerDesktopSvc.exe , SteamClientHelperHost.exe , TeraCopyMonMon.exe
After the NetSupport RAT is installed and made persistent on the host, the scripts used to set it up are deleted automatically, removing traces of the initial compromise.
Hancitor C2 traffic consists of HTTP POST URLs that end with /8/forum.php . | The infected host first generates Hancitor command and control (C2) traffic.
Hancitor C2 traffic consists of HTTP POST URLs that end with /8/forum.php .
Payloads téléchargés : DockerDesktopSvc.exe , SteamClientHelperHost.exe , TeraCopyMonMon.exe ... Stage 3 : 3 payloads depuis eu03hub.com
119 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Remote access trojan delivered in the Windows infection chain, using msedgewebview-themed C2 infrastructure for remote control.
RAT delivered via malicious Excel documents themed around COVID statistics; infections can download additional components after compromise.
Remote access trojan activity identified via network traffic, with connections from the infected host to 45.131.214[.]85 over TCP/443.
A legitimate remote access tool repurposed by attackers as a persistent remote access trojan. In this campaign it is delivered as the second-stage payload, installed via CAB/batch/VBScript components, configured for persistence, and used to take unauthorized control of infected Windows hosts.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.