Deploying NetSupport RAT via WordPress & ClickFix
ID: e5e131d8-7c6c-555f-a6fc-c353bb063c53
STIX ID: report--e5e131d8-7c6c-555f-a6fc-c353bb063c53
Feed Name: Cybereason Blog
Cybereason GSOC reports an active May 2025 campaign where attackers compromise websites and inject JavaScript to load a fake CAPTCHA that uses clipboard trickery to get Windows users to execute a command, which downloads and runs a staged NetSupport Client (client32.exe) with persistence and remote-control capabilities; the analysis includes technical details of the multi-stage chain, observed post-exploitation reconnaissance, IOCs (IPs, domains, hashes), and remediation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
