logo

NetSupport RAT Distributed Via SocGholish

ID: 7e905705-de81-5083-8311-227161704220

STIX ID: report--7e905705-de81-5083-8311-227161704220

Feed Name: Cyble Blog

Threat Score
70/100

Date Published: 2025-05-21

Date Updated: 2026-07-20

...
...

This report analyzes a SocGholish drive-by-download campaign deploying the NetSupport RAT through fake browser-update pages: users are redirected to a malicious page, download an archive containing an obfuscated JavaScript (AutoUpdater.js) that launches PowerShell to retrieve and decode payloads which drop and persist whost.exe (NetSupport client). The report documents registry persistence, C2 communication (including http://aeoi.pl/15.ico and 149.248.8.148), demonstrates post-infection capabilities, and lists IOCs (file hashes, URLs, IPs) and recommended mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.