logo

New Phishing Attack Uses Clever Microsoft Office Trick to Deploy NetSupport RAT

ID: 6416fedc-3d9f-521e-b337-7eccbc8fe520

STIX ID: report--6416fedc-3d9f-521e-b337-7eccbc8fe520

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2024-03-19

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Perception Point reports on Operation PhantomBlu, a U.S.-targeted phishing campaign that uses password-protected Word docs and OLE template injection to deliver NetSupport RAT via a ZIP containing a shortcut (.lnk) PowerShell dropper; attackers send messages through the Brevo email platform and increasingly host malicious payloads/URLs on abused cloud, CDN and Web3 services to evade detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.