RST TI Report Digest: 23 Feb 2026
ID: e2828cd8-a2b8-573d-b906-1bbadec16f15
STIX ID: report--e2828cd8-a2b8-573d-b906-1bbadec16f15
Feed Name: RST Cloud Blog
Recorded Future describes GrayCharlie, an active threat actor since mid-2023 that compromises WordPress sites to inject malicious JavaScript which redirects visitors to download the NetSupport Remote Access Trojan via deceptive browser-update and ClickFix-style lures; the campaign disproportionately targets U.S. law firm websites, uses complex infrastructure (MivoCloud, HZ Hosting), and provides extensive IOCs (many IPs, domains, URLs, and SHA-256 hashes) indicating an ongoing supply-chain style threat to the legal sector.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
