NetSupport RAT Distributed Via SocGholish
ID: 7e905705-de81-5083-8311-227161704220
STIX ID: report--7e905705-de81-5083-8311-227161704220
Feed Name: Cyble Blog
This report analyzes a SocGholish drive-by-download campaign deploying the NetSupport RAT through fake browser-update pages: users are redirected to a malicious page, download an archive containing an obfuscated JavaScript (AutoUpdater.js) that launches PowerShell to retrieve and decode payloads which drop and persist whost.exe (NetSupport client). The report documents registry persistence, C2 communication (including http://aeoi.pl/15.ico and 149.248.8.148), demonstrates post-infection capabilities, and lists IOCs (file hashes, URLs, IPs) and recommended mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
