logo

NetSupport Intrusion Results in Domain Compromise

ID: 6e86dde7-d4e3-5418-909b-d529e255eceb

STIX ID: report--6e86dde7-d4e3-5418-909b-d529e255eceb

Feed Name: The DFIR Report

Threat Score
80/100

Date Published: 2023-10-30

Date Updated: 2026-04-19

Author: editor

...
...

This DFIR report analyzes a January 2023 intrusion where threat actors used a malicious ZIP containing JavaScript to drop an obfuscated PowerShell installer that deployed NetSupport RAT, achieved persistence (registry Run key, scheduled tasks), installed OpenSSH and a reverse SSH tunnel, and used Impacket tools, SMB/WMI/RDP and additional tooling to move laterally, dump NTDS.dit and LSASS, stage data for exfiltration, and ultimately cause a full domain compromise; the report includes network and file IOCs (domains, IPs, filenames, hashes), tactics, techniques, and recommended detection artifacts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.