NetSupport Client is a legitimate remote administration product that is frequently repurposed by threat actors as a remote access trojan on Windows systems. In malicious operations it is commonly deployed in silent or stealth-oriented configurations that give operators direct interactive access to compromised hosts and enable persistent remote control.
Abuse of NetSupport Client has been observed in multiple intrusion chains. It has been delivered as a secondary payload by malware such as the YASS infostealer and has also been distributed through FakeUpdate and SocGholish-style campaigns that use compromised websites and traffic direction systems to profile visitors and present fake browser update lures. In these campaigns, victims are typically filtered and fingerprinted before the final payload is delivered, reducing exposure to researchers and automated analysis.
When used maliciously, NetSupport Client functions as a Windows RAT or backdoor. Operators use it for post-compromise access, persistence, and hands-on control of infected machines. Reported deployments include startup persistence and silent execution intended to blend with normal system activity. Its use is especially common as a follow-on access mechanism after initial infection by downloaders, fake updates, or other malware families, allowing attackers to retain access independently of the original payload.
Because NetSupport Client is commercially available software with legitimate administrative uses, malicious use is best identified through surrounding delivery context, stealth configuration, unauthorized persistence, and association with broader intrusion activity rather than by the software name alone.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
T1053.005 Scheduled Task/Job: Scheduled Task Creates scheduled task to execute PowerShell commands which further downloads and executes PowerShell scripts
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A remote access tool/backdoor additionally deployed by YASS via PowerShell, with downloaded components and configuration, persistence setup, and reporting when crypto wallet folders are detected.
A remote access trojan delivered via the FakeUpdate campaign through Parrot TDS, configured to run silently and provide direct access to compromised systems.
The final payload delivered after FakeUpdate filtering. Installed under AppData\Roaming, often masquerading as ctfmon.exe, persisted via a Run registry key, and configured for stealth and full remote access to the victim machine through attacker-controlled gateways.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.