Last seven days
- First activity
- Aug 28, 2026
- Last activity
- Sep 2, 2026
- Feed role
- C2 / Distribution
- Host form
- 34 IP / 25 hostnames
NetSupport RAT is the malicious repurposing of NetSupport Manager/NetSupport Client, a legitimate Windows remote-support product, to provide unauthorized interactive remote access to compromised endpoints.
Profile source: Mallory opens in a new tabNetSupport RAT
NetSupport RAT is the malicious repurposing of NetSupport Manager/NetSupport Client, a legitimate Windows remote-support product, to provide unauthorized interactive remote access to compromised endpoints. Threat actors deploy the signed legitimate client with its supporting configuration and runtime components, allowing them to control hosts, install follow-on malware, and potentially move laterally within affected environments. It has been observed in campaigns associated with SocGholish/FakeUpdates, BattleRoyal, UAC-0050, and other cybercriminal activity, including operations targeting Ukrainian organizations and social-engineering campaigns targeting conference attendees. Delivery chains have included phishing and social-media lures, malicious document and counterfeit installer workflows, ClickFix prompts that induce PowerShell execution, fake browser updates delivered from compromised websites, and large-scale email campaigns. Windows-focused installations have established persistence through scheduled tasks or user-level startup configuration and, in some cases, removed temporary artifacts and command-history traces to hinder forensic investigation.
C2 tracking
Derp observations, rolling seven-day window
Samples
1b723594e574c00aac2c946ff738a0454f7c24f6ebc84ae45a6af9628b08cb96 2b20eb4237ad2eab05c4a2ad261bcfd436663cf32e2a45526e17dfd3a51a095d 2fcad226b17131da4274e1b9f8f31359bdd325c9568665f08fd1f6c5d06a23ce 508e710d673802a532798e7dffa3aefcfb36eff0acef1620b8614917ac62e53e 8d793a16bf2e7153df21e2ede4b0baf6e080596073b27ecbeac6613b6a68b8d8 65d3bde6c04aa764456dd470ea17e9cdb6b7fb44b8f82f0921e958a6e44abc59 745186535109e3962ac56e535696689a7f313a2d1d97cb0d49d3907b5285eec0 94f37147a2aec1a4b9538d9a87c587c6a77c4c1c8167727fefc3227a26522f0b bcca745cf5978de27affee7d7bb1b30e421c676e3c0f9e6171114b462c7d52f2 cd3c107bc733c90ebdb6612dbab6f33d7f1308be38b9e808db2b022a798311d1 Reported operators
Beginning in early January 2025, eSentire Threat Response Unit (TRU) observed an increase in the number of incidents involving the NetSupport Remote Access Trojan (RAT).
Beginning in early January 2025, eSentire Threat Response Unit (TRU) observed an increase in the number of incidents involving the NetSupport Remote Access Trojan (RAT).
Beginning in early January 2025, eSentire Threat Response Unit (TRU) observed an increase in the number of incidents involving the NetSupport Remote Access Trojan (RAT).
Beginning in early January 2025, eSentire Threat Response Unit (TRU) observed an increase in the number of incidents involving the NetSupport Remote Access Trojan (RAT).
Since the beginning of 2025, UAC-0050 switched to NetSupport Manager for its malware operations in both January and February.
Current samples of Font_Chrome.exe are file downloaders. They retrieve follow-up malware that installs a NetSupport Manager remote access tool (RAT).
In late November to early December, Proofpoint analysts observed the activity cluster replace DarkGate with NetSupport, a legitimate remote access tool, in observed campaigns... NetSupport can enable threat actors to gain control of an infected host, install additional malware, and enable lateral movement throughout a compromised environment.
This technique is commonly used by multiple intrusion sets to distribute... RATs ( e.g. NetSupport)...
This technique is commonly used by multiple intrusion sets to distribute... RATs ( e.g. NetSupport)...
This technique is commonly used by multiple intrusion sets to distribute... RATs ( e.g. NetSupport)...
На компьютерах под управлением Windows атакующие пытались установить NetSupport RAT. Этот троян злоупотребляет легитимным инструментом удаленного администрирования NetSupport Manager и предоставляет своим операторам доступ к зараженной системе.
Similar to other RMM tools, NetSupport manager has been exploited to be used maliciously, to a point of a malicious by-product of the platform being created - aptly named NetSupport RAT.
The TA571 campaign contained at least two different command lines running different PowerShell scripts, one leading to DarkGate via a downloaded HTA-file that ran another PowerShell script and one leading to NetSupport RAT via a downloaded ZIP file.
Scarlet Goldfinch is a cluster of activity that Red Canary first observed in June 2023. This threat deceives users into downloading a file masquerading as a browser update, which starts a chain of activity eventually leading to the installation of NetSupport Manager. NetSupport Manager is an RMM tool that provides the adversary remote control over a system.
Insikt Group discovered a custom PowerShell loader named PowerNet, which decompresses and executes NetSupport RAT.
Such findings follow a report by Symantec detailing a Rogue Raticate phishing campaign involving the utilization of malicious PDFs for NetSupport RAT delivery...
In 2024-2025, that meant Evil Corp affiliates deploying WastedLocker, Cobalt Strike operators establishing persistence, and NetSupport RAT campaigns harvesting credentials at scale.
NetSupport Manager is a commercial remote administration product developed by NetSupport Ltd. It is widely deployed in enterprise environments for legitimate IT management. However, it has also been repeatedly leveraged by threat actors as a post-compromise persistence mechanism.
...UNC4108 hacking groups, with the latter spreading the NetSupport RAT and VOLTMARKER payloads.
Since 2023, TA547 typically delivers NetSupport RAT but has occasionally delivered other payloads...
Last year, however, they switched strategies, opting to misuse legitimate software, NetSupport, to maintain control over infected machines.
NetSupport Manager is another client-server remote desktop management application... ra.exe... Our sample is the NetSupportManager RAT
"...including the publicly available NetSupport RAT..."
GrayCharlie ... redirect victims to NetSupport RAT infections delivered via fake browser update pages or ClickFix techniques, ultimately resulting in Stealc and SectopRAT infections.
Exploited software
MITRE ATT&CK
Reporting
A threat actor targeted security researchers after Black Hat and DEF CON by impersonating a senior CoinDesk-linked cryptocurrency media executive on X and sending conference-planning lures through trusted services including Google Docs, GitHub Releases, and Dropbox DocSend. Huntress reported that the first lure used a booby-trapped Google Doc with a malicious Google Apps Script sidebar that asked victims for an "encryption key," profiled the host, and then steered users into staged malware delivery paths tailored to macOS and Windows systems. On macOS, victims were served a disk image resembling Atomic macOS Stealer (AMOS), while Windows targets received a fake Google API Connector update that led to a ClickOnce application, PowerShell-based loaders, and additional payloads. Huntress said the Windows chain ultimately deployed NetSupport RAT, a fake Ledger wallet application, and a local TLS-intercepting proxy built around a rogue certificate authority, indicating goals that included credential theft, cryptocurrency wallet compromise, and persistent remote access; when the first attempt failed, the actor followed up with a second malicious document disguised as a DocSend share to continue the intrusion attempt.
A public project called CertGraveyard has expanded efforts to document abused code-signing certificates used to sign malware, building a shared record of certificate abuse and helping defenders trigger revocations with certificate authorities. The project’s creator said the initiative grew out of years of reporting malicious certificates tied to malware such as SolarMarker, and has helped report more than 2,000 certificates, later growing to roughly 2,400 entries in the database. Supporting tooling includes certReport, which automates abuse reports from malware hashes using sources such as VirusTotal and MalwareBazaar, plus an API, downloadable datasets, feeds, hunting queries, and integrations with platforms including MalwareBazaar, UnpacMe, Malcat, MagicSword.io, and WDAC enforcement workflows. The database reflects a broader pattern in which threat actors repeatedly obtain or abuse valid Authenticode certificates to make malware appear trustworthy, reduce Windows warnings, and sustain delivery campaigns. Prior reporting cited SolarMarker cycling through impostor-issued certificates, FakeBat distributing signed MSI and MSIX installers, Netbounce using valid certificates and fake software branding, Dark Caracal signing Bandook variants with legitimate certificates, and Operation Red Signature abusing a stolen vendor certificate in a supply-chain intrusion. CertGraveyard’s operator said certificate authorities often act on external reports within hours, making revocation a practical disruption measure, though the project has also faced operational pressure including a major DDoS attack while handling heavy daily lookup and download volumes from defenders and malware-analysis integrations.
Microsoft reported that social-engineering lures are increasingly being used to trick users into launching malware themselves, with the ClickFix technique emerging as a major delivery method across phishing, malvertising, and compromised websites. In ClickFix attacks, victims are shown fake CAPTCHA, verification, or repair prompts that copy malicious commands to the clipboard and persuade them to run them, often leading to fileless execution through LOLBins, obfuscated PowerShell, and follow-on payloads such as Lumma Stealer, DarkGate, Latrodectus, ScreenConnect, and AMOS. Microsoft said the technique has hit thousands of enterprise and consumer devices daily and is now supported by a growing underground market of ClickFix builder kits sold on criminal forums. Fresh activity shows the tactic continuing to evolve. A SmartApeSG campaign observed on compromised web traffic redirected victims to a fake human-verification flow that fetched an HTA downloader from deltaode[.]com, retrieved a ZIP archive, and abused DLL side-loading to launch an unidentified RAT that later communicated with 89.124.79[.]98 over TCP 443. Separately, Microsoft linked the CaptiveCrunch campaign to Storm-2945, a sub-cluster of Russia-linked Midnight Blizzard, which has manipulated DNS and HTTP traffic on hospitality and other captive-portal networks to redirect travelers to phishing pages and fake browser or OS updates delivering CornFlake and ChocoShell for credential theft and espionage, including theft of browser credentials, Microsoft 365 tokens, and Wi-Fi credentials.
The Lampion banking malware operators have intensified phishing campaigns against Portuguese organizations, with activity heavily concentrated in Portugal and targeting sectors including government, finance, transportation, and private industry. Researchers said the infection chain uses ZIP attachments that lead victims to fake Portuguese-themed websites, including pages impersonating the country’s tax authority and other local organizations, to deliver social-engineering prompts that push users toward malware execution. In observed attacks, victims were tricked with a ClickFix lure into launching a malicious PowerShell command, which then fetched multiple heavily obfuscated VBScript stages designed for persistence, reconnaissance, evasion, and command-and-control communication. The malware checks for security tools and sandbox or virtualized environments, exfiltrates a Base64-encoded victim identifier to cloud-hosted infrastructure, and prepares delivery of a large DLL-based remote-access payload associated with Lampion, although one observed chain stopped short of deploying the final payload because the download command was commented out.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.