logo

NetSupport Manager: Tracking Dual-Use Remote Administration Infrastructure

ID: 7e0f6e4d-1e87-53fb-83f9-16f4db189ac1

STIX ID: report--7e0f6e4d-1e87-53fb-83f9-16f4db189ac1

Feed Name: Censys Blog

Threat Score
70/100

Date Published: 2026-03-12

Date Updated: 2026-04-27

...
...

Censys identified 25 Internet-exposed NetSupport Manager Gateway instances that respond with a distinctive HTTP Server header and heartbeat (CMD=HEARTBEAT), indicating plaintext HTTP-based relay infrastructure used for remote control; these Gateways may be legitimate but misconfigured or operated by adversaries (observed in campaigns tied to TA569 and TA505). The report details network and host detection methods, port and geographic distribution, risks of plaintext HTTP on port 443, and recommendations to validate ownership, restrict access, and monitor for unauthorized installations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.