logo

Deploying NetSupport RAT via WordPress & ClickFix

ID: e5e131d8-7c6c-555f-a6fc-c353bb063c53

STIX ID: report--e5e131d8-7c6c-555f-a6fc-c353bb063c53

Feed Name: Cybereason Blog

Threat Score
70/100

Date Published: 2025-07-07

Date Updated: 2026-04-27

Author: Cybereason Security Services Team

...
...

Cybereason GSOC reports an active May 2025 campaign where attackers compromise websites and inject JavaScript to load a fake CAPTCHA that uses clipboard trickery to get Windows users to execute a command, which downloads and runs a staged NetSupport Client (client32.exe) with persistence and remote-control capabilities; the analysis includes technical details of the multi-stage chain, observed post-exploitation reconnaissance, IOCs (IPs, domains, hashes), and remediation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.