logo

Beneath the Surface: How Hackers Turn NetSupport Against Users

ID: 05760506-2756-59bf-9161-a2151babcaaa

STIX ID: report--05760506-2756-59bf-9161-a2151babcaaa

Feed Name: McAfee Labs Blog

Threat Score
72/100

Date Published: 2023-11-27

Date Updated: 2026-04-28

Author: McAfee Labs

...
...

This McAfee Labs analysis describes multiple NetSupport RAT variants that spread via obfuscated JavaScript which launches wscript.exe and PowerShell (ExecutionPolicy Bypass) to download and execute client32.exe, persist in AppData (e.g., MsEdgeSandbox or D folders) and add registry autoruns; the report includes technical breakdowns, process trees, persistence details, sample hashes, malicious URLs, and C2 information (45.15.158.212:1412).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.