Last seven days
- First activity
- Aug 2, 2026
- Last activity
- Aug 6, 2026
- Feed role
- C2 / Distribution
- Host form
- 17 IP / 11 hostnames
NetSupport RAT is a Windows remote access trojan built through abuse or repurposing of the legitimate NetSupport Manager remote administration software.
Profile source: Mallory opens in a new tabNetSupport RAT
NetSupport RAT is a Windows remote access trojan built through abuse or repurposing of the legitimate NetSupport Manager remote administration software. It is widely observed as a second-stage or follow-on payload in criminal intrusion chains and is commonly used to provide persistent remote access for hands-on-keyboard activity after initial compromise. Reported operations have used it alongside loaders and stealers including CastleLoader, HijackLoader, Matanbuchus, StealC, CastleStealer, Remcos, and other commodity malware families.
Observed delivery chains frequently rely on social engineering rather than exploitation. NetSupport RAT has repeatedly appeared in ClickFix campaigns that impersonate CAPTCHA, browser verification, update, meeting, or support workflows and trick victims into pasting attacker-supplied commands into Windows Run or PowerShell. It has also been delivered through phishing emails, trojanized installers, malicious JavaScript downloaders, DLL sideloading, and as a payload retrieved by multi-stage loaders such as CastleLoader and Hancitor.
Once installed, NetSupport RAT provides operators with remote control of the infected Windows host and is used as a durable access mechanism across campaigns. Associated reporting ties its use to persistence, interactive post-compromise operations, data theft, and in some cases lateral movement. Campaigns delivering NetSupport RAT have targeted enterprises broadly, including technology-sector victims, and it has also appeared in opportunistic web-based and malvertising-style social-engineering operations affecting general users. In several 2025–2026 campaigns, it was one of the more common payloads observed in ClickFix-related activity and in CastleLoader clusters such as Urutyka, Garrigin, and Noidret.
C2 tracking
Derp observations, rolling seven-day window
Samples
2fcad226b17131da4274e1b9f8f31359bdd325c9568665f08fd1f6c5d06a23ce 30955adfb864533f1d6a46b25f02aa79c5c5891d0b536eb9da9d33bcaa1061db 4e5cc8cb98584335400d00f0a0803c3e0202761f3fbe50bcab3858a80df255e1 4e5cebe1908e12e8a4ed1198fb01fb87871dbe54847855b11b3540dbc47bbe88 54942b5bcfc9add448903934fc61f4e02bf2dc6378a65f0aa4af346e858fe9d3 7fe76ccceaec33d07e90e96ac144be83ed622c8af8b134d7429020e476cf4716 8e2b78e7c586e36dc3b27c78466fad735f86cdd9b4e7ecbc4c650d934a9a176b 9ba1fdde2cc64be99ce8b98fa34cd602949d13c72a7b84fa5da6828cec12c5d9 9bb96b5e7b5bce10fa59ca1e9a040129d6159a5c131c9f3f627faac04698e8f0 a1a2328ed433e0c7f7ef81919fb3141bf2faadeb4a714a6dfb56bba76cf3b8af Reported operators
На компьютерах под управлением Windows атакующие пытались установить NetSupport RAT. Этот троян злоупотребляет легитимным инструментом удаленного администрирования NetSupport Manager и предоставляет своим операторам доступ к зараженной системе.
Similar to other RMM tools, NetSupport manager has been exploited to be used maliciously, to a point of a malicious by-product of the platform being created - aptly named NetSupport RAT.
Similar to other RMM tools, NetSupport manager has been exploited to be used maliciously, to a point of a malicious by-product of the platform being created - aptly named NetSupport RAT.
The group has been linked to past campaigns that delivered dangerous tools including NetSupport RAT, Remcos RAT, StealC, and Sectop RAT.
The TA571 campaign contained at least two different command lines running different PowerShell scripts, one leading to DarkGate via a downloaded HTA-file that ran another PowerShell script and one leading to NetSupport RAT via a downloaded ZIP file.
Scarlet Goldfinch is a cluster of activity that Red Canary first observed in June 2023. This threat deceives users into downloading a file masquerading as a browser update, which starts a chain of activity eventually leading to the installation of NetSupport Manager. NetSupport Manager is an RMM tool that provides the adversary remote control over a system.
Scarlet Goldfinch is a cluster of activity that Red Canary first observed in June 2023. This threat deceives users into downloading a file masquerading as a browser update, which starts a chain of activity eventually leading to the installation of NetSupport Manager. NetSupport Manager is an RMM tool that provides the adversary remote control over a system.
Insikt Group discovered a custom PowerShell loader named PowerNet, which decompresses and executes NetSupport RAT.
Such findings follow a report by Symantec detailing a Rogue Raticate phishing campaign involving the utilization of malicious PDFs for NetSupport RAT delivery...
In 2024-2025, that meant Evil Corp affiliates deploying WastedLocker, Cobalt Strike operators establishing persistence, and NetSupport RAT campaigns harvesting credentials at scale.
While NetSupport is less commonly observed in Proofpoint campaign data at this time, there are still a handful of threat actors that distribute it as a first-stage payload via email.
While NetSupport is less commonly observed in Proofpoint campaign data at this time, there are still a handful of threat actors that distribute it as a first-stage payload via email.
NetSupport Manager is a commercial remote administration product developed by NetSupport Ltd. It is widely deployed in enterprise environments for legitimate IT management. However, it has also been repeatedly leveraged by threat actors as a post-compromise persistence mechanism.
The campaign, active as recently as March 24, 2026, delivered four separate malware payloads to a single infected host in one session: Remcos RAT, NetSupport RAT, StealC, and Sectop RAT, also known as ArechClient2.
...UNC4108 hacking groups, with the latter spreading the NetSupport RAT and VOLTMARKER payloads.
Since 2023, TA547 typically delivers NetSupport RAT but has occasionally delivered other payloads...
Last year, however, they switched strategies, opting to misuse legitimate software, NetSupport, to maintain control over infected machines.
NetSupport Manager is another client-server remote desktop management application... ra.exe... Our sample is the NetSupportManager RAT
"...including the publicly available NetSupport RAT..."
GrayCharlie ... redirect victims to NetSupport RAT infections delivered via fake browser update pages or ClickFix techniques, ultimately resulting in Stealc and SectopRAT infections.
Exploited software
MITRE ATT&CK
Reporting
Microsoft reported that social-engineering lures are increasingly being used to trick users into launching malware themselves, with the ClickFix technique emerging as a major delivery method across phishing, malvertising, and compromised websites. In ClickFix attacks, victims are shown fake CAPTCHA, verification, or repair prompts that copy malicious commands to the clipboard and persuade them to run them, often leading to fileless execution through LOLBins, obfuscated PowerShell, and follow-on payloads such as Lumma Stealer, DarkGate, Latrodectus, ScreenConnect, and AMOS. Microsoft said the technique has hit thousands of enterprise and consumer devices daily and is now supported by a growing underground market of ClickFix builder kits sold on criminal forums. Fresh activity shows the tactic continuing to evolve. A SmartApeSG campaign observed on compromised web traffic redirected victims to a fake human-verification flow that fetched an HTA downloader from deltaode[.]com, retrieved a ZIP archive, and abused DLL side-loading to launch an unidentified RAT that later communicated with 89.124.79[.]98 over TCP 443. Separately, Microsoft linked the CaptiveCrunch campaign to Storm-2945, a sub-cluster of Russia-linked Midnight Blizzard, which has manipulated DNS and HTTP traffic on hospitality and other captive-portal networks to redirect travelers to phishing pages and fake browser or OS updates delivering CornFlake and ChocoShell for credential theft and espionage, including theft of browser credentials, Microsoft 365 tokens, and Wi-Fi credentials.
The Lampion banking malware operators have intensified phishing campaigns against Portuguese organizations, with activity heavily concentrated in Portugal and targeting sectors including government, finance, transportation, and private industry. Researchers said the infection chain uses ZIP attachments that lead victims to fake Portuguese-themed websites, including pages impersonating the country’s tax authority and other local organizations, to deliver social-engineering prompts that push users toward malware execution. In observed attacks, victims were tricked with a ClickFix lure into launching a malicious PowerShell command, which then fetched multiple heavily obfuscated VBScript stages designed for persistence, reconnaissance, evasion, and command-and-control communication. The malware checks for security tools and sandbox or virtualized environments, exfiltrates a Base64-encoded victim identifier to cloud-hosted infrastructure, and prepares delivery of a large DLL-based remote-access payload associated with Lampion, although one observed chain stopped short of deploying the final payload because the download command was commented out.
Researchers reported continued activity around CastleLoader/CastleBot malware delivery chains alongside a resurgence of KongTuke, with both threats relying heavily on social-engineering lures and staged payload delivery. Red Canary said CastleLoader remained active since early 2025 and was commonly delivered through paste-and-run fake CAPTCHA or impersonation websites, while Trend Micro documented KongTuke abusing compromised WordPress sites in ClickFix-style infection flows. The campaigns reflect a broader shift toward user-assisted execution, where victims are tricked into launching malicious commands that initiate multi-stage malware retrieval. Technical analysis from IBM and Splunk tied the Castle ecosystem to a malware-as-a-service operation and detailed the tooling used after execution, including use of finger.exe to fetch batch commands, portable Python interpreters as a bring-your-own-interpreter technique, multilayer-obfuscated Python loaders, RC4-encrypted payload retrieval, and process injection into python.exe. Splunk's review of Castle RAT highlighted the client malware's tactics and ATT&CK-mapped behavior, while Red Canary noted anti-analysis checks, C2-based tasking, and detection opportunities such as repeated caret obfuscation in cmd.exe command lines. Together, the reporting shows an active loader-and-RAT ecosystem being distributed through fake verification pages and compromised web infrastructure.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.