Palo Alto Networks Unit 42 reported a phishing campaign that delivered the NetSupport Manager remote access trojan (RAT) to victim systems. The activity used malicious email lures to trick users into opening weaponized attachments or links, after which the attackers installed NetSupport Manager to gain remote control over infected hosts and establish persistent access.
The campaign highlighted how legitimate remote administration software can be repurposed for intrusion activity, allowing attackers to monitor systems, execute commands, and potentially move deeper into compromised environments. Unit 42 said Cortex XDR detected the operation, underscoring the continued risk posed by phishing-driven malware delivery and dual-use remote management tools in enterprise networks.

Get the infrastructure and lures behind it.
1 event from the most recent confirmed update back to the earliest known activity.
Palo Alto Networks Unit 42 published research on a newly observed phishing campaign that installs the NetSupport Manager remote access trojan. The report indicates Cortex XDR detected the activity and documents the campaign as an active threat development.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.