NetSupport RAT is a remote access trojan built through abuse or repurposing of the legitimate NetSupport Manager remote administration software. It is used to provide operators with persistent remote access to compromised Windows systems and has appeared repeatedly as a follow-on payload in multi-stage intrusion chains. Observed campaigns have used it alongside loaders and stealers such as CastleLoader, Hancitor, Matanbuchus, CastleStealer, Remcos, DarkGate, XWorm, AsyncRAT, and SectopRAT, indicating its role as a broadly adopted post-compromise access tool rather than a malware family tied to a single actor.
Operationally, NetSupport RAT is associated with hands-on-keyboard activity after initial compromise. Reported capabilities include persistent remote control, loading of additional payloads, and file exfiltration. In broader campaign reporting, its deployment has been linked to downstream attacker actions such as persistence, lateral movement, and sustained post-exploitation. It has also been observed as part of account-takeover-focused intrusions in which attackers combined multiple RATs and used live browser access after credential collection.
Delivery has been observed through several distinct mechanisms. Multiple 2026 campaigns distributed NetSupport RAT through ClickFix social-engineering chains that trick victims into pasting and executing malicious commands from fake verification, update, or CAPTCHA pages. It has also been delivered by phishing emails leading to obfuscated JavaScript and PowerShell downloaders, by DLL sideloading in multi-stage infections, and as a payload retrieved by malware loaders including CastleLoader and Hancitor. Campaign reporting also shows use of fake installers, fake update lures, and watering-hole compromises to initiate the infection chain before NetSupport RAT is deployed.
The malware primarily targets Windows environments. It has been seen in opportunistic criminal campaigns as well as targeted intrusions affecting sectors including technology and simulated financial and real-estate workflows. Its continued prevalence in ClickFix and loader-driven ecosystems reflects its utility as a low-friction remote access capability that blends malicious activity with legitimate remote administration tooling.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
A legitimately signed NetSupport Manager v14.12 binary -- bearing a valid GlobalSign EV code-signing certificate issued to NETSUPPORT LTD -- is being weaponized as a Remote Access Trojan across two active delivery chains.
20 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
На компьютерах под управлением Windows атакующие пытались установить NetSupport RAT. Этот троян злоупотребляет легитимным инструментом удаленного администрирования NetSupport Manager и предоставляет своим операторам доступ к зараженной системе.
Similar to other RMM tools, NetSupport manager has been exploited to be used maliciously, to a point of a malicious by-product of the platform being created - aptly named NetSupport RAT.
Similar to other RMM tools, NetSupport manager has been exploited to be used maliciously, to a point of a malicious by-product of the platform being created - aptly named NetSupport RAT.
The group has been linked to past campaigns that delivered dangerous tools including NetSupport RAT, Remcos RAT, StealC, and Sectop RAT.
The TA571 campaign contained at least two different command lines running different PowerShell scripts, one leading to DarkGate via a downloaded HTA-file that ran another PowerShell script and one leading to NetSupport RAT via a downloaded ZIP file.
Scarlet Goldfinch is a cluster of activity that Red Canary first observed in June 2023. This threat deceives users into downloading a file masquerading as a browser update, which starts a chain of activity eventually leading to the installation of NetSupport Manager. NetSupport Manager is an RMM tool that provides the adversary remote control over a system.
25 distinct techniques documented for this family, organized by ATT&CK tactic.
Opening the shortcut then ran a hidden PowerShell command, which quietly pulled and ran the next stage in memory.
An obfuscated PowerShell stager was uploaded to VirusTotal on June 18, 2026. The Urutyka campaign follows CastleLoader’s established infection chain... The obfuscated PowerShell stager unpacks a second PS1 script and contacts the download server...
We can also see that all of the files were retrieved from the same domain... and how it uses “start-bitstransfer” to retrieve them from the C2 server to the client(victim’s machine).
While observing the JS file that was downloaded, we noticed that the code is obfuscated by a generic JS obfuscator (Obfuscate.io).
Opening the shortcut then ran a hidden PowerShell command, which quietly pulled and ran the next stage in memory.
We can also see that all of the files were retrieved from the same domain... and how it uses “start-bitstransfer” to retrieve them from the C2 server to the client(victim’s machine).
CastleLoader queries its C2 via a get_tasks command. Tasks return encrypted payloads... By replicating the get_tasks request... we were able to decrypt the HTTP response and confirm the payload manifest and downstream C2s...
The obfuscated PowerShell stager unpacks a second PS1 script and contacts the download server... The python3 script downloads another python script from the C2 server... Stage 2 shellcode reaches back for the final stage 3 CastleLoader payload...
572 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
182 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A persistent remote access payload repeatedly delivered by CastleLoader across the observed campaigns.
A remote access trojan referenced as one of the payloads or tools associated with CastleLoader campaign infrastructure.
A persistent remote access payload repeatedly deployed as a final-stage capability across the CastleLoader campaign cluster.
Legitimate remote access tool that adversaries can use as a trojanized remote-control payload for unauthorized access.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.