NetSupport RAT is the designation commonly used for malicious deployments of NetSupport Manager, a legitimate remote-administration product repurposed to provide unauthorized remote control of Windows systems. These deployments generally use standard NetSupport components with attacker-controlled configuration rather than a distinct, purpose-built malware codebase.
Operators configure the client to connect through attacker-controlled NetSupport HTTP gateways, including over commonly permitted web ports. Malicious configurations enable silent operation and suppress tray icons, connection notifications, chat, and other user-facing alerts to conceal remote-control activity. Deployment scripts may rename the client and establish persistence through Startup shortcuts, scheduled tasks, Windows services, or logon mechanisms. Some campaigns hijack existing Startup shortcuts and erase Run-dialog history to reduce visible evidence of installation.
Distribution includes phishing, fake browser updates, and ClickFix fake CAPTCHA pages that persuade users to execute commands through the Windows Run dialog. NetSupport has also appeared as a secondary payload in infection chains involving QakBot, ServHelper, Amatera, GHOSTPULSE, and Matanbuchus. PowerShell-based deployment chains have extracted its components from encrypted archives or payloads concealed inside image files.
TA505 has distributed NetSupport through ServHelper variants, including variants primarily functioning as NetSupport droppers. UAT-10820 activity has deployed an unauthorized NetSupport client following Amatera infection. Other campaigns have targeted hospitality staff with booking-themed phishing and fake verification prompts. NetSupport serves as a remote-access and post-exploitation component across multiple campaigns rather than a tool exclusive to one threat actor.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Additionally, the .URL files involved exploited CVE-2023-36025, a vulnerability in Windows SmartScreen. ... The vulnerability could allow an actor to bypass the SmartScreen defenses if a user clicked on a specially crafted .URL file or a hyperlink pointing to a .URL file.
Mandiant has also identified the exploitation of Microsoft Exchange vulnerabilities, including ProxyShell and ProxyLogon, as another access point leveraged by UNC2596 likely as early as August 2021.
Mandiant has also identified the exploitation of Microsoft Exchange vulnerabilities, including ProxyShell and ProxyLogon, as another access point leveraged by UNC2596 likely as early as August 2021.
A legitimately signed NetSupport Manager v14.12 binary -- bearing a valid GlobalSign EV code-signing certificate issued to NETSUPPORT LTD -- is being weaponized as a Remote Access Trojan across two active delivery chains.
26 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Its basic functionality (data theft, spying, and execution of commands) is supplemented with another tool that is embedded for remote management of the victim's PC—namely, NetSupport RAT.
The extracted PNG payload deploys NetSupport Manager as a stock component set, renaming client32.exe to Flaut.exe, writing a client32.ini gateway configuration, and establishing persistence through a hijacked Startup shortcut.
The extracted PNG payload deploys NetSupport Manager as a stock component set, renaming client32.exe to Flaut.exe, writing a client32.ini gateway configuration, and establishing persistence through a hijacked Startup shortcut.
Branche verification.google : NetSupport Manager 12.44, renommé hypersnap.exe, est installé silencieusement via PowerShell et communique avec la passerelle paternal-angrily.com:443.
Beginning in early January 2025, eSentire Threat Response Unit (TRU) observed an increase in the number of incidents involving the NetSupport Remote Access Trojan (RAT).
Beginning in early January 2025, eSentire Threat Response Unit (TRU) observed an increase in the number of incidents involving the NetSupport Remote Access Trojan (RAT).
26 distinct techniques documented for this family, organized by ATT&CK tactic.
NetSupport Manager persistence included 'a scheduled task to reinstall itself.'
iex(irm fixconfig[.]app) pulls the loader from 144.202.4[.]36 and iex runs it in memory.
csc.exe (the .NET compiler) ... produc[es] a helper DLL in %TEMP% ... the compiler doing the work is a signed Microsoft tool.
Sensitive tokens are assembled rather than written out; numeric constants are computed with single-byte XOR; filenames, labels, and payload bytes are all base64.
What comes back is a working PNG. The payload is appended past the end of the image data and located by scanning for the byte marker 0x89 43 48 49 4D 47 00.
The loader calls Add-Type, which spawns csc.exe three times, each producing a helper DLL in %TEMP%.
Déchiffrement par XOR à clé répétée puis décompression GZip.
NetSupport ships that client as client32.exe, so a renamed copy running out of ProgramData instead of Program Files is the tell.
It then clears HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU, which erases the pasted command from the Run dialog's history.
csc.exe (the .NET compiler) ... produc[es] a helper DLL in %TEMP% ... the compiler doing the work is a signed Microsoft tool.
Before it does anything the loader reads the hostname and returns if it matches the string CLEAN ... CLEAN is a common analysis-VM hostname.
Collecte d’informations : nom de machine, nom d’utilisateur, version Windows, architecture CPU, statut administrateur.
The loader fingerprints the host through ip-api.com ... and local calls (Win32_OperatingSystem, DisplayVersion, admin check, architecture).
Before it does anything the loader reads the hostname and returns if it matches the string CLEAN ... CLEAN is a common analysis-VM hostname.
Two randomized Start-Sleep calls, each between roughly one and three and a half seconds, break up the timing before it continues.
[The loader] POSTs it all to api.telegram.org as a bot sendMessage ... [and] request[s] hxxps://fixconfig[.]app/basic.png.
879 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Legitimate remote administration software explicitly described as being abused as a RAT payload in earlier hospitality-branded spoofing campaigns using ClickFix fake CAPTCHA pages. It is not identified as a payload of the latest campaign.
Legitimate remote-access software identified here as a payload abused in earlier hotel-targeting attacks involving fake booking messages and ClickFix pages. It is background context, not a confirmed payload in the current campaign.
A legitimate remote-support application abused as a remote-access payload in the described malware campaign.
Remote-access tool associated with the same ClickFix delivery infrastructure serving VectraRAT.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.