logo

Car Insurance Emails Drives for NetSupport RAT Infection 

ID: 572ea6b8-db01-5eaa-89bd-cb7f408cbaf5

STIX ID: report--572ea6b8-db01-5eaa-89bd-cb7f408cbaf5

Feed Name: Cofense Blog

Threat Score
65/100

Date Published: 2024-03-06

Date Updated: 2026-04-27

Author: Cofense

...
...

A basic car-insurance/financial-themed phishing campaign has been observed redirecting victims via legitimate-looking marketing/Google ad links to a compromised site (blawx.com) which serves JavaScript that downloads additional stages and a ZIP archive containing a modified NetSupport RAT. The report traces the multi-stage infection chain, shows persistence via autostart registry entries, identifies C2 configuration and communications, and highlights specific artifacts (domains, JavaScript stages, archive and NetSupport files) usable as indicators of compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.