logo

Cyber Hero MDR catches NetSupport RAT

ID: 389a0b2c-adf0-5e03-9950-36573b228d19

STIX ID: report--389a0b2c-adf0-5e03-9950-36573b228d19

Feed Name: ThreatLocker Blog

Threat Score
70/100

Date Published: 2025-12-09

Date Updated: 2026-05-01

...
...

ThreatLocker observed a ClickFix social-engineering campaign that tricks users into running a crafted Run dialog command which follows a TinyURL -> approveis.info redirect to an MSI file (masquerading as a .png). The MSI executes embedded PowerShell which downloads and runs a second-stage script (u3u3l.ps1) that drops 14 files including a signed NetSupport RAT (client32.exe), establishes persistence, and clears the RunMRU registry history to erase evidence; the report includes indicators and mitigation recommendations (block Run dialog access, detect msiexec network activity, and monitor RunMRU deletion).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.