FIN7 Hacker Group Leverages Malicious Google Ads to Deliver NetSupport RAT
ID: 50502371-fd72-5858-ad63-b3b58f205e2b
STIX ID: report--50502371-fd72-5858-ad63-b3b58f205e2b
Feed Name: The Hacker News
Threat Score
**FIN7 malvertising campaign:** FIN7 has been observed using malicious Google Ads and spoofed brand websites to trick victims into downloading signed MSIX installers that run PowerShell payloads to fingerprint systems and fetch NetSupport RAT, with follow-on delivery of loaders like DICELOADER; vendors note the abuse of MSIX to bypass SmartScreen and warn of resulting data-theft and potential extortion/ransomware activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
