NetSupport RAT installed via fake update notices
ID: b0aa23bf-18da-5f43-93ef-f9734409cfcd
STIX ID: report--b0aa23bf-18da-5f43-93ef-f9734409cfcd
Feed Name: Zscaler Security Research Blog
Zscaler ThreatLabZ documents two active campaigns that compromise CMS websites (WordPress, Joomla, Drupal) by injecting redirector and template scripts to display fake Flash or font update pages; when users accept the fake updates, HTA/EXE payloads are downloaded and executed (via PowerShell), installing NetSupport RAT which persists, exfiltrates user data, and enables remote access. The report provides IOCs (malicious domains, IP 179.43.146.90, payload hashes), infection flow, and telemetry showing tens of thousands of blocked attempts and over 100,000 affected users.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
