logo

New Multi-stage JS#SMUGGLER Malware Attack Delivers ‘NetSupport RAT’ to Gain Full System Control

ID: 2fe74d1e-067e-580b-95cc-92401dc5b059

STIX ID: report--2fe74d1e-067e-580b-95cc-92401dc5b059

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2025-12-09

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

A multi-stage web-based campaign leverages obfuscated JavaScript injected into compromised sites to silently load an HTA (executed via mshta.exe) that writes and executes AES/Base64/GZIP-encrypted PowerShell in memory, ultimately downloading and installing NetSupport RAT; the actors use rotating obfuscation, device-type checks, in-browser localStorage checks, persistence via a Startup shortcut (WindowsUpdate.lnk), and attacker-controlled domains (e.g., stoneandjon.com, boriver.com, kindstki.com) as indicators.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.