logo

RST TI Report Digest: 23 Feb 2026

ID: e2828cd8-a2b8-573d-b906-1bbadec16f15

STIX ID: report--e2828cd8-a2b8-573d-b906-1bbadec16f15

Feed Name: RST Cloud Blog

Threat Score
75/100

Date Published: 2026-02-23

Date Updated: 2026-04-29

Author: RST Cloud

...
...

Recorded Future describes GrayCharlie, an active threat actor since mid-2023 that compromises WordPress sites to inject malicious JavaScript which redirects visitors to download the NetSupport Remote Access Trojan via deceptive browser-update and ClickFix-style lures; the campaign disproportionately targets U.S. law firm websites, uses complex infrastructure (MivoCloud, HZ Hosting), and provides extensive IOCs (many IPs, domains, URLs, and SHA-256 hashes) indicating an ongoing supply-chain style threat to the legal sector.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.