Skip to content

NetSupport RAT

NetSupport RAT is a Windows remote access trojan built through abuse or repurposing of the legitimate NetSupport Manager remote administration software.

Profile source: Mallory opens in a new tab

NetSupport RAT

Family profile

NetSupport RAT is a Windows remote access trojan built through abuse or repurposing of the legitimate NetSupport Manager remote administration software. It is widely observed as a second-stage or follow-on payload in criminal intrusion chains and is commonly used to provide persistent remote access for hands-on-keyboard activity after initial compromise. Reported operations have used it alongside loaders and stealers including CastleLoader, HijackLoader, Matanbuchus, StealC, CastleStealer, Remcos, and other commodity malware families.

Observed delivery chains frequently rely on social engineering rather than exploitation. NetSupport RAT has repeatedly appeared in ClickFix campaigns that impersonate CAPTCHA, browser verification, update, meeting, or support workflows and trick victims into pasting attacker-supplied commands into Windows Run or PowerShell. It has also been delivered through phishing emails, trojanized installers, malicious JavaScript downloaders, DLL sideloading, and as a payload retrieved by multi-stage loaders such as CastleLoader and Hancitor.

Once installed, NetSupport RAT provides operators with remote control of the infected Windows host and is used as a durable access mechanism across campaigns. Associated reporting ties its use to persistence, interactive post-compromise operations, data theft, and in some cases lateral movement. Campaigns delivering NetSupport RAT have targeted enterprises broadly, including technology-sector victims, and it has also appeared in opportunistic web-based and malvertising-style social-engineering operations affecting general users. In several 2025–2026 campaigns, it was one of the more common payloads observed in ClickFix-related activity and in CastleLoader clusters such as Urutyka, Garrigin, and Noidret.

Capabilities

  • Exfiltration
  • Lateral Movement
  • Persistence
  • Post Exploitation

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 2, 2026
Last activity
Aug 6, 2026
Feed role
C2 / Distribution
Host form
17 IP / 11 hostnames

Leading locations

  • US8
  • CN5
  • RU3
  • LT2
  • LU2
  • NL2
  • BR1
  • DE1
  • FR1
  • GR1
  • HK1
  • IE1

Leading providers

  • Amazon.com, Inc.2
  • CHINA UNICOM China169 Backbone2
  • Flyservers S.A.2
  • Ghosty Networks LLC2
  • Omegatech LTD2
  • Oracle Corporation2

Infrastructure traits

  • Hosting 25
  • Vpn 1

Samples

Recent associated samples

Reported operators

Threat actors

20 named in public reporting
ErrTraffic

На компьютерах под управлением Windows атакующие пытались установить NetSupport RAT. Этот троян злоупотребляет легитимным инструментом удаленного администрирования NetSupport Manager и предоставляет своим операторам доступ к зараженной системе.

FIN7

Similar to other RMM tools, NetSupport manager has been exploited to be used maliciously, to a point of a malicious by-product of the platform being created - aptly named NetSupport RAT.

Carbanak

Similar to other RMM tools, NetSupport manager has been exploited to be used maliciously, to a point of a malicious by-product of the platform being created - aptly named NetSupport RAT.

SmartApeSG

The group has been linked to past campaigns that delivered dangerous tools including NetSupport RAT, Remcos RAT, StealC, and Sectop RAT.

TA571

The TA571 campaign contained at least two different command lines running different PowerShell scripts, one leading to DarkGate via a downloaded HTA-file that ran another PowerShell script and one leading to NetSupport RAT via a downloaded ZIP file.

Scarlet Goldfinch

Scarlet Goldfinch is a cluster of activity that Red Canary first observed in June 2023. This threat deceives users into downloading a file masquerading as a browser update, which starts a chain of activity eventually leading to the installation of NetSupport Manager. NetSupport Manager is an RMM tool that provides the adversary remote control over a system.

SocGholish

Scarlet Goldfinch is a cluster of activity that Red Canary first observed in June 2023. This threat deceives users into downloading a file masquerading as a browser update, which starts a chain of activity eventually leading to the installation of NetSupport Manager. NetSupport Manager is an RMM tool that provides the adversary remote control over a system.

GrayAlpha

Insikt Group discovered a custom PowerShell loader named PowerNet, which decompresses and executes NetSupport RAT.

Rogue Raticate

Such findings follow a report by Symantec detailing a Rogue Raticate phishing campaign involving the utilization of malicious PDFs for NetSupport RAT delivery...

Indrik Spider

In 2024-2025, that meant Evil Corp affiliates deploying WastedLocker, Cobalt Strike operators establishing persistence, and NetSupport RAT campaigns harvesting credentials at scale.

UAC-0050

While NetSupport is less commonly observed in Proofpoint campaign data at this time, there are still a handful of threat actors that distribute it as a first-stage payload via email.

ZPHP

While NetSupport is less commonly observed in Proofpoint campaign data at this time, there are still a handful of threat actors that distribute it as a first-stage payload via email.

TA505

NetSupport Manager is a commercial remote administration product developed by NetSupport Ltd. It is widely deployed in enterprise environments for legitimate IT management. However, it has also been repeatedly leveraged by threat actors as a post-compromise persistence mechanism.

HANEYMANEY

The campaign, active as recently as March 24, 2026, delivered four separate malware payloads to a single infected host in one session: Remcos RAT, NetSupport RAT, StealC, and Sectop RAT, also known as ArechClient2.

UNC4108

...UNC4108 hacking groups, with the latter spreading the NetSupport RAT and VOLTMARKER payloads.

TA547

Since 2023, TA547 typically delivers NetSupport RAT but has occasionally delivered other payloads...

Bloody Wolf

Last year, however, they switched strategies, opting to misuse legitimate software, NetSupport, to maintain control over infected machines.

REF9019

NetSupport Manager is another client-server remote desktop management application... ra.exe... Our sample is the NetSupportManager RAT

RomCom

"...including the publicly available NetSupport RAT..."

GrayCharlie

GrayCharlie ... redirect victims to NetSupport RAT infections delivered via fake browser update pages or ClickFix techniques, ultimately resulting in Stealc and SectopRAT infections.

Exploited software

Vulnerabilities linked to NetSupport RAT

1 CVEs

MITRE ATT&CK

NetSupport RAT in ATT&CK

85 distinct techniques

Techniques

85 techniques
T1059.001 PowerShell T1562 Impair Defenses T1204 User Execution T1105 Ingress Tool Transfer T1036 Masquerading T1566 Phishing T1071 Application Layer Protocol T1204.002 Malicious File T1027.011 Fileless Storage T1547.001 Registry Run Keys / Startup Folder T1566.001 Spearphishing Attachment T1059 Command and Scripting Interpreter T1219 Remote Access Tools T1583 Acquire Infrastructure T1656 Impersonation T1560 Archive Collected Data T1041 Exfiltration Over C2 Channel T1555.003 Credentials from Web Browsers T1012 Query Registry T1027 Obfuscated Files or Information T1571 Non-Standard Port T1564.001 Hidden Files and Directories T1049 System Network Connections Discovery T1197 BITS Jobs T1564.003 Hidden Window T1112 Modify Registry T1047 Windows Management Instrumentation T1057 Process Discovery T1053.005 Scheduled Task T1083 File and Directory Discovery T1133 External Remote Services T1608.006 SEO Poisoning T1566.003 Spearphishing via Service T1189 Drive-by Compromise T1195 Supply Chain Compromise T1218.005 Mshta T1059.007 JavaScript T1059.003 Windows Command Shell T1021 Remote Services T1115 Clipboard Data T1566.002 Spearphishing Link T1205 Traffic Signaling T1586 Compromise Accounts T1059.005 Visual Basic T1021.002 SMB/Windows Admin Shares T1560.001 Archive via Utility T1070.004 File Deletion T1547.009 Shortcut Modification T1218.007 Msiexec T1218 System Binary Proxy Execution T1021.001 Remote Desktop Protocol T1071.001 Web Protocols T1090.002 External Proxy T1123 Audio Capture T1113 Screen Capture T1140 Deobfuscate/Decode Files or Information T1070 Indicator Removal T1095 Non-Application Layer Protocol T1082 System Information Discovery T1056 Input Capture T1547 Boot or Logon Autostart Execution T1036.005 Match Legitimate Resource Name or Location T1008 Fallback Channels T1056.001 Keylogging T1005 Data from Local System T1584.004 Server T1090.004 Domain Fronting T1125 Video Capture T1204.001 Malicious Link T1078 Valid Accounts T1134.004 Parent PID Spoofing T1055 Process Injection T1007 System Service Discovery T1543 Create or Modify System Process T1204.004 Malicious Copy and Paste T1620 Reflective Code Loading T1570 Lateral Tool Transfer T1036.004 Masquerade Task or Service T1003.003 NTDS T1583.008 Malvertising T1021.005 VNC T1053 Scheduled Task/Job T1505.003 Web Shell T1069.002 Domain Groups T1568.002 Domain Generation Algorithms

Reporting

Research mentioning NetSupport RAT

Jul 31
Malware News

CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft - Malware News - Malware Analysis, News and Indicators

Microsoft reported that social-engineering lures are increasingly being used to trick users into launching malware themselves, with the ClickFix technique emerging as a major delivery method across phishing, malvertising, and compromised websites. In ClickFix attacks, victims are shown fake CAPTCHA, verification, or repair prompts that copy malicious commands to the clipboard and persuade them to run them, often leading to fileless execution through LOLBins, obfuscated PowerShell, and follow-on payloads such as Lumma Stealer, DarkGate, Latrodectus, ScreenConnect, and AMOS. Microsoft said the technique has hit thousands of enterprise and consumer devices daily and is now supported by a growing underground market of ClickFix builder kits sold on criminal forums. Fresh activity shows the tactic continuing to evolve. A SmartApeSG campaign observed on compromised web traffic redirected victims to a fake human-verification flow that fetched an HTA downloader from deltaode[.]com, retrieved a ZIP archive, and abused DLL side-loading to launch an unidentified RAT that later communicated with 89.124.79[.]98 over TCP 443. Separately, Microsoft linked the CaptiveCrunch campaign to Storm-2945, a sub-cluster of Russia-linked Midnight Blizzard, which has manipulated DNS and HTTP traffic on hospitality and other captive-portal networks to redirect travelers to phishing pages and fake browser or OS updates delivering CornFlake and ChocoShell for credential theft and espionage, including theft of browser credentials, Microsoft 365 tokens, and Wi-Fi credentials.

Jul 31
Malware Traffic Analysis

Malware-Traffic-Analysis.net - 2026-07-31: SmartApeSG ClickFix campaign pushes unidentified RAT

Jul 24
Cyber Security News

Hackers Hide 750MB Lampion RAT Inside Fake Payment Receipt Emails

The Lampion banking malware operators have intensified phishing campaigns against Portuguese organizations, with activity heavily concentrated in Portugal and targeting sectors including government, finance, transportation, and private industry. Researchers said the infection chain uses ZIP attachments that lead victims to fake Portuguese-themed websites, including pages impersonating the country’s tax authority and other local organizations, to deliver social-engineering prompts that push users toward malware execution. In observed attacks, victims were tricked with a ClickFix lure into launching a malicious PowerShell command, which then fetched multiple heavily obfuscated VBScript stages designed for persistence, reconnaissance, evasion, and command-and-control communication. The malware checks for security tools and sandbox or virtualized environments, exfiltrates a Base64-encoded victim identifier to cloud-hosted infrastructure, and prepares delivery of a large DLL-based remote-access payload associated with Lampion, although one observed chain stopped short of deploying the final payload because the download command was commented out.

Jul 24
Cryptika

Hackers Hide 750MB Lampion RAT Inside Fake Payment Receipt Emails | Cryptika Cybersecurity

Jul 23
Scworld

Lampion banking malware continues to target Portuguese organizations | brief | SC Media

Jul 23
Cyberveille

Campagne Lampion : phishing multistage ciblant les utilisateurs portugais via de faux documents financiers | CyberVeille

Jul 23
Red Canary

Intelligence Insights: July 2026 | Red Canary

Researchers reported continued activity around CastleLoader/CastleBot malware delivery chains alongside a resurgence of KongTuke, with both threats relying heavily on social-engineering lures and staged payload delivery. Red Canary said CastleLoader remained active since early 2025 and was commonly delivered through paste-and-run fake CAPTCHA or impersonation websites, while Trend Micro documented KongTuke abusing compromised WordPress sites in ClickFix-style infection flows. The campaigns reflect a broader shift toward user-assisted execution, where victims are tricked into launching malicious commands that initiate multi-stage malware retrieval. Technical analysis from IBM and Splunk tied the Castle ecosystem to a malware-as-a-service operation and detailed the tooling used after execution, including use of finger.exe to fetch batch commands, portable Python interpreters as a bring-your-own-interpreter technique, multilayer-obfuscated Python loaders, RC4-encrypted payload retrieval, and process injection into python.exe. Splunk's review of Castle RAT highlighted the client malware's tactics and ATT&CK-mapped behavior, while Red Canary noted anti-analysis checks, C2-based tasking, and detection opportunities such as repeated caret obfuscation in cmd.exe command lines. Together, the reporting shows an active loader-and-RAT ecosystem being distributed through fake verification pages and compromised web infrastructure.

Jul 23
Dark Reading

Brazilian Banking Trojan Actively Spreading in Portugal

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.