JS#SMUGGLER is a multi-stage malware campaign identified by Securonix that delivers NetSupport RAT. Reported tradecraft includes hidden iframes, obfuscated JavaScript, silent redirectors, “junk code” JavaScript for EDR evasion, and fileless PowerShell execution. The infection chain begins when a user visits a compromised website, where an obfuscated JavaScript loader—reported in some cases from boriver.com—checks whether the victim is on a desktop system and is designed to run only once per user. A subsequent hidden HTA stage is executed via mshta.exe; this payload is described as protected with AES-256-ECB, Base64, and GZIP, with the main infection content decoded in memory rather than written to disk. The final stage uses PowerShell to download a compressed payload, including from kindstki.com, and installs NetSupport RAT, a legitimate remote administration tool abused for malicious purposes. Reported capabilities of the resulting RAT access include remote desktop control, file access, command execution, and surveillance. Persistence is achieved by extracting files to C:\ProgramData\CommunicationLayer\ and creating a disguised Startup shortcut such as WindowsUpdate.lnk. Mentioned infrastructure associated with the campaign includes boriver.com, stoneandjon.com, and kindstki.com. The campaign is described as stealth-focused and intended to provide long-term covert access to victim systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
JS#SMUGGLER is a multi-stage JavaScript-based loader that uses hidden iframes and obfuscated code to silently redirect users and deliver payloads such as NetSupport RAT.
JS#SMUGGLER is a multi-stage loader using hidden iframes and obfuscated JavaScript to deliver NetSupport RAT.
JavaScript-based malware/loader that uses obfuscated “junk code” and fileless PowerShell execution to evade EDR and deploy a secondary payload (NetSupport RAT).
JS#SMUGGLER is a multi-stage JavaScript-based loader campaign designed to evade detection and deliver NetSupport RAT. It uses obfuscated JavaScript, encrypted HTA payloads, and fileless techniques to install the RAT and establish persistence.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.