Researchers reported continued abuse of fake browser and software update pages on compromised websites to trick Windows users into installing malware, with multiple investigations tying the lure to delivery of NetSupport Manager RAT and broader SocGholish/FakeUpdates activity. Trellix described a campaign in which injected JavaScript redirected visitors to counterfeit Chrome update pages, then launched a staged infection chain using JavaScript, batch files, VBScript, curl, and a portable 7-Zip utility to install NetSupport while avoiding PowerShell. Mandiant documented a similar chain in which a disguised archive and scripts unpacked NetSupport from %AppData%, established persistence through startup shortcuts and registry artifacts, and enabled remote desktop control, file transfer, system inventory, application launch, and geolocation.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
12 events from the most recent confirmed update back to the earliest known activity.
Trellix disclosed technical details and indicators for the fake browser update campaign, including injected script paths, staged downloaders using batch files and curl instead of PowerShell, and a NetSupport gateway at 5.252.178.48:443.
Cybereason said it observed an increase in attacks involving SocGholish and Zloader from December 2021 onward, and published analysis of three attack chains using fake updates or installers to deliver follow-on malware.
Trellix said its Advanced Research Center first noticed an ongoing campaign in late June 2023 in which compromised websites displayed fake Chrome update pages that led victims to install NetSupport Manager RAT.
Proofpoint released an overview of threat actor TA569 and its SocGholish activity, adding public reporting on the actor and malware ecosystem.
Walmart Global Tech published analysis tying an IRS-themed fake CAPTCHA campaign using VHD/LNK, PowerShell, .NET/XLL loaders, and NetSupport RAT to SocGholish through shared infrastructure, code, and characteristic NetSupport configuration patterns. The report also said more recent SocGholish activity delivered a Cobalt Strike loader tracked by antivirus vendors as Blister.
Sucuri said it had detected SocGholish or NDSW/NDSX on more than 25,000 sites since the beginning of January 2022, and noted 61,000 infected websites had been detected in the prior year alone.
NHS Digital published a cyber alert describing SocGholish as a malware delivery framework used in drive-by-download and watering hole attacks, commonly disguised as browser updates. The notice associated SocGholish with Indrik Spider and said it had been observed delivering payloads including WastedLocker, NetSupport RAT, Hades, and Dridex.
In April 2021, the victim organization in the Wasted Locker case received a TLP:Amber warning from a government cyber defense organization stating its systems might be under attacker control or impacted by a cyber event, referencing PRODAFT’s SilverFish report.
In October 2020, attackers attributed by Truesec to Evil Corp used a fake Chrome update delivered via a drive-by compromise, likely through the SocGholish framework, to gain initial access to a major corporation.
SANS ISC published analysis of a SocGholish campaign in which compromised websites redirected users to fake Firefox or Chrome update pages that delivered a JavaScript or HTA downloader and ultimately a NetSupport RAT-based payload. The report included persistence details, delivery differences by browser, and network and file indicators tied to the infection chain.
Mandiant published analysis of a fake software update attack chain that used a disguised archive and startup persistence to install the legitimate NetSupport Manager tool as a remote access trojan.
Sucuri reported that the SocGholish/FakeUpdates JavaScript malware framework had been used since at least 2017 to redirect visitors from compromised websites to fake browser update pages that deliver malware.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
12 references tracked. Mallory keeps watching after this page renders.
trellix.com
Open sourcecybereason.com
Open sourceproofpoint.com
Open sourceblog.sucuri.net
Open sourceisc.sans.edu
Open sourcemandiant.com
Open sourceprodaft.com
Open sourcecrowdstrike.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.