New Multi-stage JS#SMUGGLER Malware Attack Delivers ‘NetSupport RAT’ to Gain Full System Control
ID: 2fe74d1e-067e-580b-95cc-92401dc5b059
STIX ID: report--2fe74d1e-067e-580b-95cc-92401dc5b059
Feed Name: cybersecurityNews.com
A multi-stage web-based campaign leverages obfuscated JavaScript injected into compromised sites to silently load an HTA (executed via mshta.exe) that writes and executes AES/Base64/GZIP-encrypted PowerShell in memory, ultimately downloading and installing NetSupport RAT; the actors use rotating obfuscation, device-type checks, in-browser localStorage checks, persistence via a Startup shortcut (WindowsUpdate.lnk), and attacker-controlled domains (e.g., stoneandjon.com, boriver.com, kindstki.com) as indicators.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
