NetSupport RAT is the malicious use of the legitimate NetSupport Manager remote administration software as a remote access trojan on compromised Windows systems. In intrusion activity, operators typically deploy the NetSupport client together with attacker-controlled configuration data so the software connects back to hostile infrastructure and provides interactive remote control. Once installed, it can give an operator broad access to the victim host, including remote desktop control, command execution, file management, clipboard interaction, information gathering, delivery of additional payloads, and in some campaigns support for lateral movement within a compromised environment.
The malware is widely used as a commodity post-compromise access tool across cybercrime ecosystems rather than being exclusive to a single actor. It has been observed in campaigns associated with SocGholish, SmartApeSG, TA505-linked ServHelper activity, UAC-0050, and the Proofpoint-tracked BattleRoyal cluster, and it is also distributed by malware services and loaders such as PrivateLoader, OpcJacker, and other downloader chains. It has appeared alongside or after families including DarkGate, Remcos, SmokeLoader, Lumma, Predator Stealer, FlawedAmmy, Cobalt Strike, and MineBridge, reflecting its role as a flexible follow-on access payload.
Observed delivery chains are heavily social-engineering driven. Common infection vectors include fake browser or software update pages, compromised websites serving drive-by lures, phishing pages masquerading as legitimate software or games, malicious email campaigns, cracked-software ecosystems, and staged downloader chains using JavaScript, HTA, VBScript, batch files, PowerShell, NSIS, MSI, or Inno Setup installers. Several campaigns used fake Chrome or Firefox updates, HoeflerText font-update lures, or ZIP archives containing script-based downloaders that retrieved and unpacked NetSupport components.
On infected hosts, NetSupport RAT commonly establishes persistence through Windows Run entries, Startup-folder shortcuts, scheduled tasks, or other autorun mechanisms. Some campaigns rename or modify the NetSupport client to evade detection, while others package it with auxiliary scripts, DLLs, or archives. Threat actors frequently use it as an initial foothold or lightweight backdoor to profile victims, maintain access, deploy stealers or other malware, and continue hands-on-keyboard operations.
Although derived from legitimate administration software, NetSupport RAT in malicious deployments functions as a Windows backdoor and remote access trojan used in financially motivated intrusion, initial access brokerage, and espionage-adjacent operations. It has targeted a broad range of sectors, with repeated reporting involving organizations in North America and Ukraine as well as enterprise victims reached through mass-malspam and fake-update campaigns.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Additionally, the .URL files involved exploited CVE-2023-36025, a vulnerability in Windows SmartScreen. ... The vulnerability could allow an actor to bypass the SmartScreen defenses if a user clicked on a specially crafted .URL file or a hyperlink pointing to a .URL file.
Mandiant has also identified the exploitation of Microsoft Exchange vulnerabilities, including ProxyShell and ProxyLogon, as another access point leveraged by UNC2596 likely as early as August 2021.
Mandiant has also identified the exploitation of Microsoft Exchange vulnerabilities, including ProxyShell and ProxyLogon, as another access point leveraged by UNC2596 likely as early as August 2021.
A legitimately signed NetSupport Manager v14.12 binary -- bearing a valid GlobalSign EV code-signing certificate issued to NETSUPPORT LTD -- is being weaponized as a Remote Access Trojan across two active delivery chains.
24 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Since the beginning of 2025, UAC-0050 switched to NetSupport Manager for its malware operations in both January and February.
Current samples of Font_Chrome.exe are file downloaders. They retrieve follow-up malware that installs a NetSupport Manager remote access tool (RAT).
In late November to early December, Proofpoint analysts observed the activity cluster replace DarkGate with NetSupport, a legitimate remote access tool, in observed campaigns... NetSupport can enable threat actors to gain control of an infected host, install additional malware, and enable lateral movement throughout a compromised environment.
This technique is commonly used by multiple intrusion sets to distribute... RATs ( e.g. NetSupport)...
This technique is commonly used by multiple intrusion sets to distribute... RATs ( e.g. NetSupport)...
This technique is commonly used by multiple intrusion sets to distribute... RATs ( e.g. NetSupport)...
26 distinct techniques documented for this family, organized by ATT&CK tactic.
Anyone who was affected by this phishing campaign should operate under the assumption that their data has been compromised and that the threat actor attempted to steal their passwords.
The beginning of an infection chain starts with a legitimate website with injected code... The end result looked like the image below... Fake browser update page seen after visiting a legitimate website.
Microsoft is warning of an ongoing COVID-19 themed phishing campaign that installs the NetSupport Manager remote administration tool.
The NetSupport Manager RAT is extracted using the downloaded 7-zip utility and executed through scheduled tasks in the victim computer by the downloaded “2.bat” file.
The NetSupport RAT used in this campaign further drops multiple components, including several .dll, .ini, and other .exe files, a VBScript, and an obfuscated PowerSploit-based PowerShell script.
the PowerShell script will then launch the CMD file, which will extract the sharchivedmngr
The NetSupport RAT used in this campaign further drops multiple components, including several .dll, .ini, and other .exe files, a VBScript, and an obfuscated PowerSploit-based PowerShell script. | As this document contains malicious macros, it will prompt the user to 'Enable Content'. Once clicked, malicious macros will be executed to download and install the NetSupport Manager client from a remote site.
This script’s only purpose was to download a NetSupport Manager archive hosted on the following URL.
If someone clicked through enough security warnings, they might very well infect a vulnerable Windows host.
The NetSupport Manager RAT is extracted using the downloaded 7-zip utility and executed through scheduled tasks in the victim computer by the downloaded “2.bat” file.
Anyone who was affected by this phishing campaign should operate under the assumption that their data has been compromised and that the threat actor attempted to steal their passwords.
The NetSupport Manager RAT is extracted using the downloaded 7-zip utility and executed through scheduled tasks in the victim computer by the downloaded “2.bat” file.
Anyone who was affected by this phishing campaign should operate under the assumption that their data has been compromised and that the threat actor attempted to steal their passwords.
The injected code is highly-obfuscated... The downloaded zip archive contained a JavaScript file with heavily obfuscated Javascript... This NetSupport RAT-based malware package was sent as a 10MB ASCII text file consisting of hexadecimal characters. This is encoded data, and the file was saved to my lab host and decoded to a zip archive containing the malware package.
The report’s Tactics, Techniques and Procedures section lists T1027.002 Obfuscated Files or Information: Software Packing.
In this particular attack, the NetSupport Manager client will be saved as the dwm.exe file under a random %AppData% folder and launched. As the remote administration tool is masquerading as the legitimate Desktop Windows Manager executable, it may not be noticed as unusual by users viewing Task Manager.
Traffic generated by NetSupport RAT-based malware package: 81.17.21[.]98 port 443... POST http://81.17.21[.]98/fakeurl.htm ... 62.172.138[.]35 port 80 - geo.netsupportsoftware[.]com - GET /location/loca.asp
the javascript file ... will begin checking in to a C2 ... Along with communicating over HTTPS, this sample talked to irsbusinessaudit[.]net ... GatewayAddress=sjvuvja.com:443
697 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Remote access malware delivered as a bundle and installed under AppData\Roaming\NetSupport\Service.exe, with C2 check-in activity noted in detections.
A persistent remote access payload repeatedly delivered by CastleLoader across the observed campaigns.
A remote access trojan referenced as one of the payloads or tools associated with CastleLoader campaign infrastructure.
A remote administration tool abused as malware in ClickFix campaigns to provide unauthorized remote access to affected systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.