The threat actor GrayCharlie compromised WordPress websites and used them as malware delivery points, redirecting visitors to attacker-controlled pages that pushed NetSupport RAT and the Stealc information stealer. The campaign turned legitimate sites into staging infrastructure, allowing the attackers to infect users who visited the hacked pages and expand access beyond the initial web compromises.
Reporting indicates the operation combined website compromise with malware distribution and data theft, using NetSupport RAT for remote access and Stealc to harvest sensitive information from infected systems. The activity highlights the dual risk posed by compromised WordPress environments: website owners lose control of trusted web assets, while visitors face malware infection and credential theft through seemingly legitimate sites.

Pull IOCs and campaign context straight into your stack.
1 event from the most recent confirmed update back to the earliest known activity.
Security reporting described a GrayCharlie campaign in which compromised WordPress sites were used to distribute NetSupport RAT and Stealc malware for data theft. The two references report the same underlying activity and do not provide a more specific incident date than their publication timeframe.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.