NetSupport RAT is a Windows remote access trojan derived from abuse of the legitimate NetSupport Manager remote administration product. It is widely used as a second-stage payload in criminal intrusion chains and social-engineering campaigns, giving operators interactive access to compromised systems. Reported capabilities include remote control of infected hosts, execution of additional payloads, file exfiltration, and broader post-compromise activity consistent with sustained hands-on-keyboard access. It is frequently positioned as a foothold that can enable follow-on malware deployment, including other stealers, loaders, and ransomware.
The malware is commonly delivered through phishing and ClickFix-style social-engineering campaigns that trick users into executing attacker-supplied commands, often via PowerShell or Windows Run dialogs. It has also been observed in chains involving obfuscated JavaScript downloaders, trojanized software, malicious MSI installers, DLL sideloading, compromised websites, fake CAPTCHA or verification pages, and fake browser or software update lures. NetSupport RAT has additionally appeared as a follow-on payload from broader malware delivery ecosystems including SocGholish/FakeUpdates and Hancitor, as well as campaigns associated with SmartApeSG.
Observed tradecraft includes persistence through scheduled tasks, Startup-folder placement, and Run-key mechanisms, as well as use of sideloading and legitimate tooling to reduce suspicion. NetSupport RAT is regularly associated with financially motivated intrusion activity and has been linked in reporting to threat actors and ecosystems including FIN7, TA569-linked delivery chains, ErrTraffic-enabled ClickFix operations, and SmartApeSG campaigns. Targeting has included enterprise users broadly, with specific reporting noting technology-sector victims and exposure through compromised media, retail, and WordPress-based websites. In contemporary campaigns, NetSupport RAT is often one component of multi-stage intrusion workflows used for credential access, data theft, remote operations, and staging of additional malware.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
A legitimately signed NetSupport Manager v14.12 binary -- bearing a valid GlobalSign EV code-signing certificate issued to NETSUPPORT LTD -- is being weaponized as a Remote Access Trojan across two active delivery chains.
20 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
На компьютерах под управлением Windows атакующие пытались установить NetSupport RAT. Этот троян злоупотребляет легитимным инструментом удаленного администрирования NetSupport Manager и предоставляет своим операторам доступ к зараженной системе.
Similar to other RMM tools, NetSupport manager has been exploited to be used maliciously, to a point of a malicious by-product of the platform being created - aptly named NetSupport RAT.
Similar to other RMM tools, NetSupport manager has been exploited to be used maliciously, to a point of a malicious by-product of the platform being created - aptly named NetSupport RAT.
The group has been linked to past campaigns that delivered dangerous tools including NetSupport RAT, Remcos RAT, StealC, and Sectop RAT.
The TA571 campaign contained at least two different command lines running different PowerShell scripts, one leading to DarkGate via a downloaded HTA-file that ran another PowerShell script and one leading to NetSupport RAT via a downloaded ZIP file.
Scarlet Goldfinch is a cluster of activity that Red Canary first observed in June 2023. This threat deceives users into downloading a file masquerading as a browser update, which starts a chain of activity eventually leading to the installation of NetSupport Manager. NetSupport Manager is an RMM tool that provides the adversary remote control over a system.
29 distinct techniques documented for this family, organized by ATT&CK tactic.
T1133 (External Remote Services) - доступ через легитимный удалённый сервис (тактики: Initial Access, Persistence)
Clubfoot Wolf gained initial access via phishing emails disguised as invoices or requests for proposal.
The exe file uses a few techniques for persistence: Scheduled tasks Startup Menu file saving Registry Key
Launching a malicious LNK file triggers the execution of a Base64-encoded PowerShell command.
Launching a malicious LNK file triggers the execution of a Base64-encoded PowerShell command.
The exe file uses a few techniques for persistence: Scheduled tasks Startup Menu file saving Registry Key
T1133 (External Remote Services) - доступ через легитимный удалённый сервис (тактики: Initial Access, Persistence)
We can also see that all of the files were retrieved from the same domain... and how it uses “start-bitstransfer” to retrieve them from the C2 server to the client(victim’s machine).
Decodes, decrypts, and executes the PowerShell code that persists NetSupport Manager by creating the following Run registry entry: [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] VoiceAssistant = "%LOCALAPPDATA%\VoiceAssistant\voiceassist.exe.exe"
The exe file uses a few techniques for persistence: Scheduled tasks Startup Menu file saving Registry Key
Decodes, decrypts, and executes the PowerShell code that persists NetSupport Manager by creating the following Run registry entry: [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] VoiceAssistant = "%LOCALAPPDATA%\VoiceAssistant\voiceassist.exe.exe"
While observing the JS file that was downloaded, we noticed that the code is obfuscated by a generic JS obfuscator (Obfuscate.io).
This style of attack is designed to bypass basic user skepticism by mimicking standard web elements, making it particularly effective in mass-targeting scenarios.
We can also see that all of the files were retrieved from the same domain... and how it uses “start-bitstransfer” to retrieve them from the C2 server to the client(victim’s machine).
C2: 216.126.237[.]122:443 Confirmed via JA3 TLS fingerprinting and malware config extraction
Downloads a ZIP archive from hxxps://crop[.]sh/OSRXf5B ... and saves it under a random name [A-Za-z0-9]{7}.zip in %TEMP%.
563 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
175 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
NetSupport RAT3
A remote access trojan or remote access tool used as a ClickFix-delivered payload in the campaigns discussed.
Remote access malware distributed as one of several payloads in the fake verification page ClickFix campaign.
Remote access trojan mentioned as one of several malware variants seen in ClickFix-related incidents.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.