GrayCharlie is a financially motivated cyber threat actor active since at least mid-2023 that compromises WordPress websites and injects externally hosted JavaScript to deliver malware to site visitors. The cluster overlaps with SmartApeSG and has also been referred to as ZPHP and HANEYMANEY. Its operations have included supply-chain-style compromises affecting multiple U.S. law firm websites, with reporting indicating some intrusions may have occurred through a shared service provider or common WordPress administration stack. GrayCharlie’s core tradecraft centers on website compromise, malicious script injection, and social engineering. After compromising a WordPress site, the actor inserts script tags that load attacker-controlled JavaScript. That code profiles the visitor environment and redirects selected users to fake browser update pages or ClickFix-style fake CAPTCHA lures. These lures are designed to trick users into executing commands that install NetSupport RAT. GrayCharlie has also used NetSupport RAT as a delivery mechanism for follow-on payloads including the Stealc infostealer and SectopRAT. Observed post-compromise behavior includes host reconnaissance, surveillance, file operations, persistence, and secondary payload deployment. In ClickFix-related infections, persistence has been established through autorun mechanisms. Researchers also observed later-stage deployment of SectopRAT via DLL sideloading. Infrastructure associated with GrayCharlie has been tied primarily to MivoCloud and HZ Hosting Ltd, and reporting has identified two main NetSupport RAT command-and-control clusters distinguished by certificate and licensing characteristics. Some operational evidence suggests at least part of the actor’s operator base is Russian-speaking. GrayCharlie appears to target victims opportunistically across industries, but the United States has been the most frequently observed target in available reporting, with a notable concentration on law firms. The actor’s dominant motivation is financial gain, and its campaigns have emphasized malware delivery, credential and information theft, persistence, reconnaissance, and broader post-exploitation activity rather than ransomware or destructive operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
20 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Compromise of WordPress sites via injected external JavaScript for visitor profiling and malware delivery, using fake update lures/ClickFix-style prompts; infections linked to NetSupport tooling followed by Stealc and SectopRAT.
Financially motivated supply-chain style campaign leveraging compromised WordPress sites of U.S. law firms (likely via a shared IT/marketing provider) to inject malicious JavaScript that redirects victims to fake browser updates or fake CAPTCHAs, coercing execution of a PowerShell command via the Windows Run dialog to install NetSupport RAT; subsequently used for surveillance/file operations and to deliver Stealc infostealer and SectopRAT.
Compromises WordPress sites to inject malicious JavaScript that profiles visitors and delivers social-engineering lures (fake browser updates and ClickFix-style fake CAPTCHAs) to get users to execute payloads, primarily deploying NetSupport RAT and additional stealers/RATs. Activity includes supply-chain compromise of an IT services provider to reach multiple US law firms.
Compromises WordPress sites to redirect traffic to fake browser-update pages to deliver remote access trojans (RATs).
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.