Last seven days
- First activity
- Sep 4, 2026
- Last activity
- Sep 11, 2026
- Feed role
- C2 / Distribution
- Host form
- 11 IP / 10 hostnames
NetSupport Manager is a legitimate commercial remote-access product whose client component is frequently repurposed as a remote access trojan (RAT) in malicious campaigns.
Profile source: Mallory opens in a new tabNetSupport RAT
NetSupport Manager is a legitimate commercial remote-access product whose client component is frequently repurposed as a remote access trojan (RAT) in malicious campaigns. Adversaries deploy customized clients configured for silent, unauthorized remote control of Windows endpoints. Malicious deployments have supported operator access to compromised hosts, delivery of additional payloads, and lateral movement; observed packages have also used scheduled tasks or Registry-based mechanisms to retain access. NetSupport Manager has been delivered through ClickFix lures, phishing and social-engineering campaigns, counterfeit software installers, fake browser-update pages, and malware-loader chains. It has appeared in activity associated with UAT-10820, UAC-0050, BattleRoyal, SocGholish, EITest, and TA505-related ServHelper operations, among others. Its use does not by itself establish attribution because the software is commercially available and widely abused by unrelated threat actors.
C2 tracking
Derp observations, rolling seven-day window
Samples
4e5cc8cb98584335400d00f0a0803c3e0202761f3fbe50bcab3858a80df255e1 54942b5bcfc9add448903934fc61f4e02bf2dc6378a65f0aa4af346e858fe9d3 65ba3988d38f83b9ee1f31cafa5bd37dc6b72279f5618aac94d71a904efa0cac c2214a8b8c88c91a009891f3f10bbb2d8aa18a15580bd12c82dfcf2477f0c846 c26e2475ef60ba969bb66c9b464b498efb1da0bf7360ff7545c1db3b707bdbed 46c40af9624ba9be8af28cfc7d3847552a93089b4b4db07a66547081f29f9891 4e428fb03df8cdf9d154b14eb7d4e2fa1d147a835a8c6e81b1863115f3cff464 da4e45d152926a4bd7339543decbe6dc5511ed2a3f6df13153749929347a49c4 f41ff860abd5c8d4c742f063542b9014c53a9f926dedb130ce3b74cb2e0ffc21 1c98d149fd358406a2fa77fc2c3bbf4f65d04d87f81a2402eab155b186b97cbe Reported operators
Branche verification.google : NetSupport Manager 12.44, renommé hypersnap.exe, est installé silencieusement via PowerShell et communique avec la passerelle paternal-angrily.com:443.
Beginning in early January 2025, eSentire Threat Response Unit (TRU) observed an increase in the number of incidents involving the NetSupport Remote Access Trojan (RAT).
Beginning in early January 2025, eSentire Threat Response Unit (TRU) observed an increase in the number of incidents involving the NetSupport Remote Access Trojan (RAT).
Beginning in early January 2025, eSentire Threat Response Unit (TRU) observed an increase in the number of incidents involving the NetSupport Remote Access Trojan (RAT).
Beginning in early January 2025, eSentire Threat Response Unit (TRU) observed an increase in the number of incidents involving the NetSupport Remote Access Trojan (RAT).
Since the beginning of 2025, UAC-0050 switched to NetSupport Manager for its malware operations in both January and February.
Current samples of Font_Chrome.exe are file downloaders. They retrieve follow-up malware that installs a NetSupport Manager remote access tool (RAT).
In late November to early December, Proofpoint analysts observed the activity cluster replace DarkGate with NetSupport, a legitimate remote access tool, in observed campaigns... NetSupport can enable threat actors to gain control of an infected host, install additional malware, and enable lateral movement throughout a compromised environment.
This technique is commonly used by multiple intrusion sets to distribute... RATs ( e.g. NetSupport)...
This technique is commonly used by multiple intrusion sets to distribute... RATs ( e.g. NetSupport)...
This technique is commonly used by multiple intrusion sets to distribute... RATs ( e.g. NetSupport)...
На компьютерах под управлением Windows атакующие пытались установить NetSupport RAT. Этот троян злоупотребляет легитимным инструментом удаленного администрирования NetSupport Manager и предоставляет своим операторам доступ к зараженной системе.
Similar to other RMM tools, NetSupport manager has been exploited to be used maliciously, to a point of a malicious by-product of the platform being created - aptly named NetSupport RAT.
The TA571 campaign contained at least two different command lines running different PowerShell scripts, one leading to DarkGate via a downloaded HTA-file that ran another PowerShell script and one leading to NetSupport RAT via a downloaded ZIP file.
Scarlet Goldfinch is a cluster of activity that Red Canary first observed in June 2023. This threat deceives users into downloading a file masquerading as a browser update, which starts a chain of activity eventually leading to the installation of NetSupport Manager. NetSupport Manager is an RMM tool that provides the adversary remote control over a system.
Insikt Group discovered a custom PowerShell loader named PowerNet, which decompresses and executes NetSupport RAT.
Such findings follow a report by Symantec detailing a Rogue Raticate phishing campaign involving the utilization of malicious PDFs for NetSupport RAT delivery...
In 2024-2025, that meant Evil Corp affiliates deploying WastedLocker, Cobalt Strike operators establishing persistence, and NetSupport RAT campaigns harvesting credentials at scale.
NetSupport Manager is a commercial remote administration product developed by NetSupport Ltd. It is widely deployed in enterprise environments for legitimate IT management. However, it has also been repeatedly leveraged by threat actors as a post-compromise persistence mechanism.
...UNC4108 hacking groups, with the latter spreading the NetSupport RAT and VOLTMARKER payloads.
Since 2023, TA547 typically delivers NetSupport RAT but has occasionally delivered other payloads...
Last year, however, they switched strategies, opting to misuse legitimate software, NetSupport, to maintain control over infected machines.
NetSupport Manager is another client-server remote desktop management application... ra.exe... Our sample is the NetSupportManager RAT
"...including the publicly available NetSupport RAT..."
GrayCharlie ... redirect victims to NetSupport RAT infections delivered via fake browser update pages or ClickFix techniques, ultimately resulting in Stealc and SectopRAT infections.
Exploited software
MITRE ATT&CK
Reporting
Cisco Talos identified a months-long ClickFix cryptocurrency-theft campaign that tricks users into injecting malicious JavaScript into Chrome or installing it through Tampermonkey. Lures impersonate leaked reports of cryptocurrency-exchange API flaws and promise SwapZone or SimpleSwap trading bonuses. The scripts use Google Sheets and the Google Visualization API for command-and-control, hiding second-stage retrieval within trusted docs.google.com traffic, then replace cryptocurrency deposit addresses in webpages, intercepted responses, and the clipboard. Talos linked 49 Bitcoin wallets to the operation; 24 active wallets received 0.159 BTC, roughly $10,000 in early August 2026. ClickFix techniques continue to enable broader malware delivery as well as browser-based theft. A blocked July 2026 intrusion used phishing to induce in-memory PowerShell execution, followed by a loader, process injection into svchost.exe or explorer.exe, and deployment of PureLogs Stealer targeting browser credentials, cookies, banking data, and cryptocurrency wallets. Earlier activity tracked by Proofpoint showed ClearFake and TA571 using fake browser or certificate warnings and malicious clipboard content to persuade victims to manually run PowerShell, delivering stealers, RATs, loaders, and cryptominers. Organizations should treat unexpected browser verification prompts and copy-paste instructions as high-risk, while monitoring for browser script injection, anomalous Google-hosted script retrieval, and credential or wallet-address manipulation.
A threat actor targeted security researchers after Black Hat and DEF CON by impersonating a senior CoinDesk-linked cryptocurrency media executive on X and sending conference-planning lures through trusted services including Google Docs, GitHub Releases, and Dropbox DocSend. Huntress reported that the first lure used a booby-trapped Google Doc with a malicious Google Apps Script sidebar that asked victims for an "encryption key," profiled the host, and then steered users into staged malware delivery paths tailored to macOS and Windows systems. On macOS, victims were served a disk image resembling Atomic macOS Stealer (AMOS), while Windows targets received a fake Google API Connector update that led to a ClickOnce application, PowerShell-based loaders, and additional payloads. Huntress said the Windows chain ultimately deployed NetSupport RAT, a fake Ledger wallet application, and a local TLS-intercepting proxy built around a rogue certificate authority, indicating goals that included credential theft, cryptocurrency wallet compromise, and persistent remote access; when the first attempt failed, the actor followed up with a second malicious document disguised as a DocSend share to continue the intrusion attempt.
A public project called CertGraveyard has expanded efforts to document abused code-signing certificates used to sign malware, building a shared record of certificate abuse and helping defenders trigger revocations with certificate authorities. The project’s creator said the initiative grew out of years of reporting malicious certificates tied to malware such as SolarMarker, and has helped report more than 2,000 certificates, later growing to roughly 2,400 entries in the database. Supporting tooling includes certReport, which automates abuse reports from malware hashes using sources such as VirusTotal and MalwareBazaar, plus an API, downloadable datasets, feeds, hunting queries, and integrations with platforms including MalwareBazaar, UnpacMe, Malcat, MagicSword.io, and WDAC enforcement workflows. The database reflects a broader pattern in which threat actors repeatedly obtain or abuse valid Authenticode certificates to make malware appear trustworthy, reduce Windows warnings, and sustain delivery campaigns. Prior reporting cited SolarMarker cycling through impostor-issued certificates, FakeBat distributing signed MSI and MSIX installers, Netbounce using valid certificates and fake software branding, Dark Caracal signing Bandook variants with legitimate certificates, and Operation Red Signature abusing a stolen vendor certificate in a supply-chain intrusion. CertGraveyard’s operator said certificate authorities often act on external reports within hours, making revocation a practical disruption measure, though the project has also faced operational pressure including a major DDoS attack while handling heavy daily lookup and download volumes from defenders and malware-analysis integrations.
Microsoft reported that social-engineering lures are increasingly being used to trick users into launching malware themselves, with the ClickFix technique emerging as a major delivery method across phishing, malvertising, and compromised websites. In ClickFix attacks, victims are shown fake CAPTCHA, verification, or repair prompts that copy malicious commands to the clipboard and persuade them to run them, often leading to fileless execution through LOLBins, obfuscated PowerShell, and follow-on payloads such as Lumma Stealer, DarkGate, Latrodectus, ScreenConnect, and AMOS. Microsoft said the technique has hit thousands of enterprise and consumer devices daily and is now supported by a growing underground market of ClickFix builder kits sold on criminal forums. Fresh activity shows the tactic continuing to evolve. A SmartApeSG campaign observed on compromised web traffic redirected victims to a fake human-verification flow that fetched an HTA downloader from deltaode[.]com, retrieved a ZIP archive, and abused DLL side-loading to launch an unidentified RAT that later communicated with 89.124.79[.]98 over TCP 443. Separately, Microsoft linked the CaptiveCrunch campaign to Storm-2945, a sub-cluster of Russia-linked Midnight Blizzard, which has manipulated DNS and HTTP traffic on hospitality and other captive-portal networks to redirect travelers to phishing pages and fake browser or OS updates delivering CornFlake and ChocoShell for credential theft and espionage, including theft of browser credentials, Microsoft 365 tokens, and Wi-Fi credentials.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.