Car Insurance Emails Drives for NetSupport RAT Infection
ID: 572ea6b8-db01-5eaa-89bd-cb7f408cbaf5
STIX ID: report--572ea6b8-db01-5eaa-89bd-cb7f408cbaf5
Feed Name: Cofense Blog
A basic car-insurance/financial-themed phishing campaign has been observed redirecting victims via legitimate-looking marketing/Google ad links to a compromised site (blawx.com) which serves JavaScript that downloads additional stages and a ZIP archive containing a modified NetSupport RAT. The report traces the multi-stage infection chain, shows persistence via autostart registry entries, identifies C2 configuration and communications, and highlights specific artifacts (domains, JavaScript stages, archive and NetSupport files) usable as indicators of compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
