How NetSupport RAT Abuses Legitimate Remote Admin Tool
ID: 47a8179c-9376-5731-a679-b5393b658c29
STIX ID: report--47a8179c-9376-5731-a679-b5393b658c29
Feed Name: Resources-2
NetSupport RAT is a legitimate remote administration tool that has been repurposed by threat actors for unauthorized surveillance and persistent remote access. The report details social-engineering delivery methods (fake browser updates, ClickFix, malicious ISOs/game lures), dropped components (client32.exe, client32.ini, DLLs), core capabilities (audio/video/screenshots, input locking, file transfer, remote commands), post-exploitation activities (credential harvesting, lateral movement using Impacket, use of ProcDump, ransomware deployment), and persistence techniques (Run registry entry, Startup shortcuts, scheduled tasks). It includes example IOCs (filenames and registry paths) and recommends testing defenses with the Picus Security Validation Platform.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
