logo

GrayAlpha Uses Diverse Infection Vectors to Deploy PowerNet Loader and NetSupport RAT

ID: 2c21f4e4-445a-5f35-b5bf-c6688db253a7

STIX ID: report--2c21f4e4-445a-5f35-b5bf-c6688db253a7

Feed Name: Recorded Future Blog

Threat Score
80/100

Date Published: 2025-06-13

Date Updated: 2026-04-28

...
...

Insikt Group links new infrastructure and custom loaders (PowerNet and MaskBat) to GrayAlpha — an operator overlapping FIN7 — which deploys NetSupport RAT via fake browser-update pages, malicious 7‑Zip download sites, and the previously undocumented TAG‑124 TDS; the report provides domains, IPs, ASN/hosting attribution, historical context of FIN7 activity, and mitigation guidance including allow‑listing, detection rules, and monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.