Skip to content

NetSupport RAT

NetSupport RAT is the malicious repurposing of NetSupport Manager/NetSupport Client, a legitimate Windows remote-support product, to provide unauthorized interactive remote access to compromised endpoints.

Profile source: Mallory opens in a new tab

NetSupport RAT

Family profile

NetSupport RAT is the malicious repurposing of NetSupport Manager/NetSupport Client, a legitimate Windows remote-support product, to provide unauthorized interactive remote access to compromised endpoints. Threat actors deploy the signed legitimate client with its supporting configuration and runtime components, allowing them to control hosts, install follow-on malware, and potentially move laterally within affected environments. It has been observed in campaigns associated with SocGholish/FakeUpdates, BattleRoyal, UAC-0050, and other cybercriminal activity, including operations targeting Ukrainian organizations and social-engineering campaigns targeting conference attendees. Delivery chains have included phishing and social-media lures, malicious document and counterfeit installer workflows, ClickFix prompts that induce PowerShell execution, fake browser updates delivered from compromised websites, and large-scale email campaigns. Windows-focused installations have established persistence through scheduled tasks or user-level startup configuration and, in some cases, removed temporary artifacts and command-history traces to hinder forensic investigation.

Capabilities

  • Defense Evasion
  • Lateral Movement
  • Persistence
  • Post Exploitation

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 28, 2026
Last activity
Sep 2, 2026
Feed role
C2 / Distribution
Host form
34 IP / 25 hostnames

Leading locations

  • US16
  • CN9
  • DE5
  • NL5
  • RU5
  • CH3
  • SG3
  • FR2
  • LU2
  • BR1
  • FI1
  • GR1

Leading providers

  • Cloudflare, Inc.7
  • CHINA UNICOM China169 Backbone3
  • FEMO IT SOLUTIONS LIMITED3
  • Omegatech LTD3
  • Oracle Corporation3
  • Amazon.com, Inc.2

Infrastructure traits

  • Hosting 48
  • Anycast 7

Samples

Recent associated samples

Reported operators

Threat actors

24 named in public reporting
Mustard Tempest

Beginning in early January 2025, eSentire Threat Response Unit (TRU) observed an increase in the number of incidents involving the NetSupport Remote Access Trojan (RAT).

HANEYMANEY

Beginning in early January 2025, eSentire Threat Response Unit (TRU) observed an increase in the number of incidents involving the NetSupport Remote Access Trojan (RAT).

ZPHP

Beginning in early January 2025, eSentire Threat Response Unit (TRU) observed an increase in the number of incidents involving the NetSupport Remote Access Trojan (RAT).

SmartApeSG

Beginning in early January 2025, eSentire Threat Response Unit (TRU) observed an increase in the number of incidents involving the NetSupport Remote Access Trojan (RAT).

UAC-0050

Since the beginning of 2025, UAC-0050 switched to NetSupport Manager for its malware operations in both January and February.

EITest

Current samples of Font_Chrome.exe are file downloaders. They retrieve follow-up malware that installs a NetSupport Manager remote access tool (RAT).

BattleRoyal

In late November to early December, Proofpoint analysts observed the activity cluster replace DarkGate with NetSupport, a legitimate remote access tool, in observed campaigns... NetSupport can enable threat actors to gain control of an infected host, install additional malware, and enable lateral movement throughout a compromised environment.

UNC3319

This technique is commonly used by multiple intrusion sets to distribute... RATs ( e.g. NetSupport)...

FIN7

This technique is commonly used by multiple intrusion sets to distribute... RATs ( e.g. NetSupport)...

UNC4536

This technique is commonly used by multiple intrusion sets to distribute... RATs ( e.g. NetSupport)...

ErrTraffic

На компьютерах под управлением Windows атакующие пытались установить NetSupport RAT. Этот троян злоупотребляет легитимным инструментом удаленного администрирования NetSupport Manager и предоставляет своим операторам доступ к зараженной системе.

Carbanak

Similar to other RMM tools, NetSupport manager has been exploited to be used maliciously, to a point of a malicious by-product of the platform being created - aptly named NetSupport RAT.

TA571

The TA571 campaign contained at least two different command lines running different PowerShell scripts, one leading to DarkGate via a downloaded HTA-file that ran another PowerShell script and one leading to NetSupport RAT via a downloaded ZIP file.

Scarlet Goldfinch

Scarlet Goldfinch is a cluster of activity that Red Canary first observed in June 2023. This threat deceives users into downloading a file masquerading as a browser update, which starts a chain of activity eventually leading to the installation of NetSupport Manager. NetSupport Manager is an RMM tool that provides the adversary remote control over a system.

GrayAlpha

Insikt Group discovered a custom PowerShell loader named PowerNet, which decompresses and executes NetSupport RAT.

Rogue Raticate

Such findings follow a report by Symantec detailing a Rogue Raticate phishing campaign involving the utilization of malicious PDFs for NetSupport RAT delivery...

INDRIK SPIDER

In 2024-2025, that meant Evil Corp affiliates deploying WastedLocker, Cobalt Strike operators establishing persistence, and NetSupport RAT campaigns harvesting credentials at scale.

TA505

NetSupport Manager is a commercial remote administration product developed by NetSupport Ltd. It is widely deployed in enterprise environments for legitimate IT management. However, it has also been repeatedly leveraged by threat actors as a post-compromise persistence mechanism.

UNC4108

...UNC4108 hacking groups, with the latter spreading the NetSupport RAT and VOLTMARKER payloads.

TA547

Since 2023, TA547 typically delivers NetSupport RAT but has occasionally delivered other payloads...

Bloody Wolf

Last year, however, they switched strategies, opting to misuse legitimate software, NetSupport, to maintain control over infected machines.

REF9019

NetSupport Manager is another client-server remote desktop management application... ra.exe... Our sample is the NetSupportManager RAT

RomCom

"...including the publicly available NetSupport RAT..."

GrayCharlie

GrayCharlie ... redirect victims to NetSupport RAT infections delivered via fake browser update pages or ClickFix techniques, ultimately resulting in Stealc and SectopRAT infections.

Exploited software

Vulnerabilities linked to NetSupport RAT

4 CVEs

MITRE ATT&CK

NetSupport RAT in ATT&CK

87 distinct techniques

Techniques

87 techniques
T1204.002 Malicious File T1614 System Location Discovery T1113 Screen Capture T1027.013 Encrypted/Encoded File T1033 System Owner/User Discovery T1082 System Information Discovery T1070 Indicator Removal T1059.001 PowerShell T1027 Obfuscated Files or Information T1036.001 Invalid Code Signature T1588.002 Tool T1016 System Network Configuration Discovery T1071 Application Layer Protocol T1071.001 Web Protocols T1070.004 File Deletion T1027.002 Software Packing T1219 Remote Access Tools T1608.004 Drive-by Target T1112 Modify Registry T1566 Phishing T1105 Ingress Tool Transfer T1140 Deobfuscate/Decode Files or Information T1566.002 Spearphishing Link T1204 User Execution T1027.009 Embedded Payloads T1027.003 Steganography T1547.001 Registry Run Keys / Startup Folder T1090.001 Internal Proxy T1566.003 Spearphishing via Service T1036 Masquerading T1189 Drive-by Compromise T1649 Steal or Forge Authentication Certificates T1656 Impersonation T1095 Non-Application Layer Protocol T1553.002 Code Signing T1041 Exfiltration Over C2 Channel T1059.005 Visual Basic T1566.001 Spearphishing Attachment T1078 Valid Accounts T1204.001 Malicious Link T1059.003 Windows Command Shell T1059.007 JavaScript T1211 Exploitation for Defense Evasion T1571 Non-Standard Port T1053.005 Scheduled Task T1547 Boot or Logon Autostart Execution T1547.009 Shortcut Modification T1560 Archive Collected Data T1115 Clipboard Data T1083 File and Directory Discovery T1012 Query Registry T1059 Command and Scripting Interpreter T1218.005 Mshta T1204.004 Malicious Copy and Paste T1573 Encrypted Channel T1562 Impair Defenses T1027.011 Fileless Storage T1583 Acquire Infrastructure T1555.003 Credentials from Web Browsers T1564.001 Hidden Files and Directories T1049 System Network Connections Discovery T1197 BITS Jobs T1564.003 Hidden Window T1047 Windows Management Instrumentation T1057 Process Discovery T1133 External Remote Services T1608.006 SEO Poisoning T1195 Supply Chain Compromise T1021 Remote Services T1205 Traffic Signaling T1586 Compromise Accounts T1021.002 SMB/Windows Admin Shares T1560.001 Archive via Utility T1218.007 Msiexec T1218 System Binary Proxy Execution T1021.001 Remote Desktop Protocol T1090.002 External Proxy T1123 Audio Capture T1056 Input Capture T1036.005 Match Legitimate Resource Name or Location T1008 Fallback Channels T1056.001 Keylogging T1005 Data from Local System T1584.004 Server T1090.004 Domain Fronting T1125 Video Capture T1134.004 Parent PID Spoofing

Reporting

Research mentioning NetSupport RAT

Aug 19
Itsecurityguru

Fake Crypto Exec Used Booby-Trapped Google Doc to Target Security Researcher After DEF CON - IT Security Guru

A threat actor targeted security researchers after Black Hat and DEF CON by impersonating a senior CoinDesk-linked cryptocurrency media executive on X and sending conference-planning lures through trusted services including Google Docs, GitHub Releases, and Dropbox DocSend. Huntress reported that the first lure used a booby-trapped Google Doc with a malicious Google Apps Script sidebar that asked victims for an "encryption key," profiled the host, and then steered users into staged malware delivery paths tailored to macOS and Windows systems. On macOS, victims were served a disk image resembling Atomic macOS Stealer (AMOS), while Windows targets received a fake Google API Connector update that led to a ClickOnce application, PowerShell-based loaders, and additional payloads. Huntress said the Windows chain ultimately deployed NetSupport RAT, a fake Ledger wallet application, and a local TLS-intercepting proxy built around a rogue certificate authority, indicating goals that included credential theft, cryptocurrency wallet compromise, and persistent remote access; when the first attempt failed, the actor followed up with a second malicious document disguised as a DocSend share to continue the intrusion attempt.

Aug 19
Huntress

Post-DEF CON Phishing Uses Malicious Google Doc to Deliver Malware | Huntress

Aug 15
Github Web

GitHub - tjnel/certgraveyard_yara: Automated YARA rule generation from the Cert Central compromised certificate database. · GitHub

A public project called CertGraveyard has expanded efforts to document abused code-signing certificates used to sign malware, building a shared record of certificate abuse and helping defenders trigger revocations with certificate authorities. The project’s creator said the initiative grew out of years of reporting malicious certificates tied to malware such as SolarMarker, and has helped report more than 2,000 certificates, later growing to roughly 2,400 entries in the database. Supporting tooling includes certReport, which automates abuse reports from malware hashes using sources such as VirusTotal and MalwareBazaar, plus an API, downloadable datasets, feeds, hunting queries, and integrations with platforms including MalwareBazaar, UnpacMe, Malcat, MagicSword.io, and WDAC enforcement workflows. The database reflects a broader pattern in which threat actors repeatedly obtain or abuse valid Authenticode certificates to make malware appear trustworthy, reduce Windows warnings, and sustain delivery campaigns. Prior reporting cited SolarMarker cycling through impostor-issued certificates, FakeBat distributing signed MSI and MSIX installers, Netbounce using valid certificates and fake software branding, Dark Caracal signing Bandook variants with legitimate certificates, and Operation Red Signature abusing a stolen vendor certificate in a supply-chain intrusion. CertGraveyard’s operator said certificate authorities often act on external reports within hours, making revocation a practical disruption measure, though the project has also faced operational pressure including a major DDoS attack while handling heavy daily lookup and download volumes from defenders and malware-analysis integrations.

Jul 31
Malware News

CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft - Malware News - Malware Analysis, News and Indicators

Microsoft reported that social-engineering lures are increasingly being used to trick users into launching malware themselves, with the ClickFix technique emerging as a major delivery method across phishing, malvertising, and compromised websites. In ClickFix attacks, victims are shown fake CAPTCHA, verification, or repair prompts that copy malicious commands to the clipboard and persuade them to run them, often leading to fileless execution through LOLBins, obfuscated PowerShell, and follow-on payloads such as Lumma Stealer, DarkGate, Latrodectus, ScreenConnect, and AMOS. Microsoft said the technique has hit thousands of enterprise and consumer devices daily and is now supported by a growing underground market of ClickFix builder kits sold on criminal forums. Fresh activity shows the tactic continuing to evolve. A SmartApeSG campaign observed on compromised web traffic redirected victims to a fake human-verification flow that fetched an HTA downloader from deltaode[.]com, retrieved a ZIP archive, and abused DLL side-loading to launch an unidentified RAT that later communicated with 89.124.79[.]98 over TCP 443. Separately, Microsoft linked the CaptiveCrunch campaign to Storm-2945, a sub-cluster of Russia-linked Midnight Blizzard, which has manipulated DNS and HTTP traffic on hospitality and other captive-portal networks to redirect travelers to phishing pages and fake browser or OS updates delivering CornFlake and ChocoShell for credential theft and espionage, including theft of browser credentials, Microsoft 365 tokens, and Wi-Fi credentials.

Jul 31
Malware Traffic Analysis

Malware-Traffic-Analysis.net - 2026-07-31: SmartApeSG ClickFix campaign pushes unidentified RAT

Jul 28
Sekoia

Exposing FakeBat loader: distribution methods and adversary infrastructure

Jul 24
Cyber Security News

Hackers Hide 750MB Lampion RAT Inside Fake Payment Receipt Emails

The Lampion banking malware operators have intensified phishing campaigns against Portuguese organizations, with activity heavily concentrated in Portugal and targeting sectors including government, finance, transportation, and private industry. Researchers said the infection chain uses ZIP attachments that lead victims to fake Portuguese-themed websites, including pages impersonating the country’s tax authority and other local organizations, to deliver social-engineering prompts that push users toward malware execution. In observed attacks, victims were tricked with a ClickFix lure into launching a malicious PowerShell command, which then fetched multiple heavily obfuscated VBScript stages designed for persistence, reconnaissance, evasion, and command-and-control communication. The malware checks for security tools and sandbox or virtualized environments, exfiltrates a Base64-encoded victim identifier to cloud-hosted infrastructure, and prepares delivery of a large DLL-based remote-access payload associated with Lampion, although one observed chain stopped short of deploying the final payload because the download command was commented out.

Jul 24
Cryptika

Hackers Hide 750MB Lampion RAT Inside Fake Payment Receipt Emails | Cryptika Cybersecurity

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.