MaskBat is a custom obfuscated loader identified by Recorded Future Insikt Group and also referenced by CYFIRMA in activity associated with GrayAlpha, a threat cluster assessed to overlap with FIN7. Reporting states that MaskBat has similarities to FakeBat and contains strings linked to GrayAlpha. It is used in infection chains that ultimately lead to NetSupport RAT deployment; specifically, Recorded Future reported that the fake browser update infection vector uses MaskBat to execute NetSupport RAT. GrayAlpha’s broader delivery ecosystem was observed using fake browser update pages, fake 7-Zip download sites, and the TAG-124 traffic distribution system, with all three vectors resulting in NetSupport RAT infections, although PowerNet rather than MaskBat was reported for the latter two paths. Since at least April 2024, GrayAlpha’s fake browser update lures have impersonated products and services including Google Meet, LexisNexis, Asana, AIMP, SAP Concur, CNN, the Wall Street Journal, and Advanced IP Scanner. High-confidence attribution in the provided content links MaskBat to GrayAlpha/FIN7-associated operations and to malware delivery rather than standalone post-compromise functionality. No specific file hashes, domains, or IP indicators were provided for MaskBat itself in the supplied content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Insikt Group identified another custom loader, referred to as MaskBat, that has similarities to FakeBat but is obfuscated and contains strings linked to GrayAlpha.
Insikt Group identified another custom loader, referred to as MaskBat, that has similarities to FakeBat but is obfuscated and contains strings linked to GrayAlpha.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Obfuscated custom loader with similarities to FakeBat; associated with GrayAlpha infrastructure and fake update/software download delivery.
Custom loader used in the fake browser update infection chain to execute NetSupport RAT; reported as obfuscated and having similarities to FakeBat, with strings linked to GrayAlpha.
A custom obfuscated loader linked to GrayAlpha, described as a customized variant similar to FakeBat and used in infection chains leading to NetSupport RAT.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.